We use Splunk to support legacy reporting, publishing scheduled search results as documents to remote AD network shares. In many cases, we overwrite the previous version of the file.
Is there a way to create an alert triggered when a file fails to publish (e.g. problems with network, share, share permissions, locked file, etc.)?