Alerting

How to set up a custom email alert notification when a file is not present?

jugalkinariwala
Explorer

I need to write a custom alert that generates an email notification when a file is not present.

I currently have a daily alert (9pm) set up to notify via email if a .error file is present or not.
If the file is present an email including the file is generated.

Now I want to set up a custom email message that is generated when the file is not present.
For example, "No file was generated so there is no file attached".

Labels (3)
0 Karma
1 Solution

manjunathmeti
SplunkTrust
SplunkTrust

You can clone/copy same alert and set Trigger Condition to Number of Results is equal to 0 and edit alert action Send email add message in Message field.

View solution in original post

0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

You can clone/copy same alert and set Trigger Condition to Number of Results is equal to 0 and edit alert action Send email add message in Message field.

0 Karma

jugalkinariwala
Explorer

For example -
Current scenario -
I have an alert which looks into directory whether an .error file is present or not daily around 9:00 pm .
If it is present it emails the file .

Requirement-
If a file is not present I need to email with a custom text that the file is not present .

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please elaborate on your use case. Where is the file? Who or what is generating it? Is it monitored by Splunk?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...