Getting Data In

Monitoring file on unix and alerting based on some condition on the same file

abhijitsaoji
Explorer

I have set file monitoring, file is placed on the Unix . I am able to see the events being indexed in the Splunk however my alerting is not working. on the same file I have set-up some conditional alerting, I want an alert to be raised if particular text appears in the file however it is not triggering.any idea?

0 Karma

skalliger
Motivator

To troubleshoot this, we need atleast two things: example data and the SPL (your query) which should fire.

Skalli

0 Karma

abhijitsaoji
Explorer

hey, thanks for the reply. I can't give actual search, but this should do. as

my search in the saved alert:
source="/opt/splunk/akash_test/test" host="XXX" sourcetype="XXX" "test"

as it was not working just to test I was running this above search in my alert. I am editing the file and adding word test in it so that my Alert catches it and send email but its not happening. its a real time search and file is placed on Unix. As i mentioned data is getting indexed in the Splunk I can see it in the Search.

Example data:
test
ABC
test
xxx
test

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...