Alerting

How to set up a custom email alert notification when a file is not present?

jugalkinariwala
Explorer

I need to write a custom alert that generates an email notification when a file is not present.

I currently have a daily alert (9pm) set up to notify via email if a .error file is present or not.
If the file is present an email including the file is generated.

Now I want to set up a custom email message that is generated when the file is not present.
For example, "No file was generated so there is no file attached".

Labels (3)
0 Karma
1 Solution

manjunathmeti
Champion

You can clone/copy same alert and set Trigger Condition to Number of Results is equal to 0 and edit alert action Send email add message in Message field.

View solution in original post

0 Karma

manjunathmeti
Champion

You can clone/copy same alert and set Trigger Condition to Number of Results is equal to 0 and edit alert action Send email add message in Message field.

0 Karma

jugalkinariwala
Explorer

For example -
Current scenario -
I have an alert which looks into directory whether an .error file is present or not daily around 9:00 pm .
If it is present it emails the file .

Requirement-
If a file is not present I need to email with a custom text that the file is not present .

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please elaborate on your use case. Where is the file? Who or what is generating it? Is it monitored by Splunk?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...

Enterprise Security Content Update (ESCU) | New Releases

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise ...