Alerting

How to set up an alert email to trigger whenever a file is updated or modified and include the changes in the email?

raby1996
Path Finder

Hi all,

I have a monitor set up which monitors the mod-time on a file and reindexes the new one if available. I would like to set up alerts so that whenever a file is "updated or modified" it sends an email, possibly with the changes in the email. I would use the unique problem number associated with each file as well as the queue that it is relevant to ( they are both fields) I.E.

Original File
______________________________________________________
John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
________________________________________________________



    Modified File
    _______________________________________________________

    John's Queue-

    Problem Number- 1234

    Problem Text-

    The problem seems to be associated with a Disk Drive

    Update- The problem turned out to be the cable not the disk drive
    ______________________________________________________________________

This would trigger an alert that would send out an email which would hopefully send out either the new event or just the updated portion, if this is not possible than a simple alert would suffice. My end goal is to achieve one of the 3 scenarios listed below. Thank you in advance.

Email scenario 1
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the changes are listed below

"Update- The problem turned out to be the cable not the disk drive"
_______________________________________________________________________

Email scenario 2
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the updated event is listed below

John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
Update- The problem turned out to be the cable not the disk drive
_______________________________________________________________________


Email scenario 3
___________________________________________________________________

Hello John, problem numer 1234 has been modified
_______________________________________________________________________
0 Karma

raby1996
Path Finder

It is configured to re-index if the mod_time changes, should i change it? Also the content comes in as one event, this contains the problem number and all the text and information associated with it.

0 Karma

somesoni2
Revered Legend

So you've configure crcSalt in inputs.conf to re-index the file if the content changes??
How are the event broken, does whole file content comes as one event OR each line as one event?

0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...