How to monitor Windows folder path, send alert if no data is written to the said shared folder or windows path?
You could do it easily in SPL I thought for this. Just do the normal monitoring of the directory/folder. in SPL, just search if no update has been made to any file in last xx minutes
disabled = false
index = my_index
sourcetype = my:monitor:sourcetype
and in your SPL do something
index=my_index sourcetype=my:monitor:sourcetype earliest=-30m latest=now
|stats count by sourcetype
| appendpipe [ stats count | where count=0 | eval host="EMPTY" ]
| search sourcetype=EMPTY
So if its empty trigger an alert or some logic
Hi Koshyk, i will try your suggestion. I will keep you posted.