I have data like this:
A B On
C D Off
Now I want to generate an email alert if this search result changes over last 5 minutes. For example:
1. If status of any two items already present in search result changes, generate an alert.
2. If a new row gets added, generate an alert.
3. If a rwo gets deleted, generate an alert.
Save the result 5 minutes ago in the lookup file and use the diff command.
Is it the desired behavior?
https://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Diff
Do these events have proper timestamps? Are they from a DB? Can you paste one or two of the actual events?