Alerting

Help with query to notify when date is older than x amount of days

goken
New Member

Hi all,

 

I have a table called active_services.csv.
One of the fields is called Report_Date

Date value is in the following format 20220124.
The CSV file is automatically updated weekly but sometimes fails and requires manual intervention.

I need help with a query so I can setup an alert to notify me when the report date value is older than X amount of days.

Please help.

Thank you for your help in advance.

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval days=floor((relative_time(now(),"@d")-strptime(report_date,"%Y%m%d"))/(60*60*24))
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @goken,

I suppose that you are ingesting the active_services.csv in an index.

So you could run a search like this (where X=30 days):

index=your_index
| eval Diff=strptime(Report_Date,"%Y%m%d")-86400*30
| where Diff>0

 In this way, if you have results there are events outdated and you can create an alert with this search.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...