Monitoring Splunk

Can Splunk send a file as attachment without reading the content or data in the file ?

vchennuri
Engager

Can Splunk send a file as attachment without reading the content or data in the file

0 Karma

vchennuri
Engager

A file is generated every day having data of 10 to 20 lines in a location with the difference in file name. Can splunk read the data in generated file and send the file as an email alert whenever that new file is generated ?

0 Karma

solarboyz1
Builder

Sort of...

You would monitor the location the files are produced:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Monitorfilesanddirectorieswithinputs.conf

You would create a search looking for new events from the input you just created.

Assuming your inputs, timestamps, and timezones are set correctly, any new events would indicate a new file.

In which case, you would schedule a search every X minutes, configure the email to generate a single email, and attach the search results.

0 Karma

solarboyz1
Builder

I dont know of any way for Splunk to attach a non-search produced file to an email using the standard "Send Email" alert action.

This can be accomplished by creating an alert action, which could send an email and attach a document:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Alert/Configuringscriptedalerts

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Send it where? What is your use case?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...