Alerting

How do I configure an alert for missing files from different directories?

kpavan
Path Finder

Hi all,

I need help creating an alert for the difference of 2 directories. Let's say: sender directory has files 4 but receiver directory has 2. Now, I need to configure an alert for 2 missing files with names/details from receiver directory.

Getting the below outputs from each directory on a scheduled basis (1hr), I need to compare 2 directories and get the output for the missing file names and trigger an alert.

Sender Directory
[root] ➤ ls -l
total 0
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file1.txt
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file2.txt
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file3.txt
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file4.txt

Receiver Directory
[root] ➤ ls -l
total 0
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file1.txt
-rwx------ 1 Users UsersGrp 0 Dec 3 13:16 file2.txt

Please help me with queries to configure alert.

Thanks in advance!

Tags (2)
0 Karma

tom_frotscher
Builder

Hi,

as a simple first approach it could be enough to:

  1. set your time range to the last hour an
  2. extract the filename with help of regex if not already done
  3. do a | stats count by filename

The result should always be 2 if every file is present in both directories. If it is not 2, you could trigger your alert.

Greetings

Tom

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...