Getting Data In

monitoring file



I was just wondering if Splunk can be sceheduled to monitor a file regularly, and send out alerts if this file does not get updated for a specific time period , lets say for 5 minutes. Please help me in doing so, if possible.

Thanks, Nitin.

Tags (1)


Yes, sort-of. I am assuming this file is a logfile, and there are timestamped events in it. If Splunk is indexing this log file you could schedule a saved search with a conditional alert in Splunk that does something like:

source=/path/to/my/log/file earliest=-5m@m 

And only fires the alert if the results returned are <= 0.


I do that now for several of my log files...

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!