Alerting

How to create an email alert if any log file is not updated for 2 days?

ksarode
Explorer

I have created a CSV which contains all the log files that are required. I want to create an alert if any log file is not updated for 2 days.

0 Karma

rojith
New Member

You can create a new alert using Settings > Searching, report and Alert section.
In the alert Serach, you can write a simple Search to get receive data in regard to the logs for the time frame of 2 days.
In the Alert Trigger Condition, check the Number of Results=0
And set the Trigger Action as Email and give the relevant details for the email alerts..

0 Karma

skoelpin
SplunkTrust
SplunkTrust

This won't scale at all.. What happens when you have 100TB/day deployment with millions of logs you're monitoring?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

This is going to be difficult to maintain. You should checkout MetaWoot instead

https://splunkbase.splunk.com/app/2949/

0 Karma

ksarode
Explorer

yup i ll try that but if i want to do it by normal method what query i should use

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Once again, your begging for problems by wanting to do it "the normal way". You will have many false alerts, have to maintain a lookup when adding new sources etc..

0 Karma

ksarode
Explorer

ok then i ll install the app and will do that

0 Karma

skoelpin
SplunkTrust
SplunkTrust

MetaWoot can monitor the tsidx files at the host level and make managing this much easier. Please upvote/accept if this answered your question

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...