Whenever anyone updates test.csv Lookup table I want to get an alert.
Note: The update is done via Lookup editor and *Save Lookup* button is clicked.
Thanks for your response. I read in the documentation fschange was deprecated in the version 5 and I am using Splunk Enterprise version 8.1.5.
Can you please suggest an alternate solution?
I'd appreciate your help.
fschange is deprecated, but still works. I know of no alternative.
I'd look into setting up an fschange input on the lookup file and define an alert to trigger when an event is received from the input.