Splunk AppDynamics

how to monitor a file for content and send email if content available...

CommunityUser
Splunk Employee
Splunk Employee

Hi,

As an AppD beginner, loads of time, I get stuck with the easiest problems..   😞    right now I am trying to create a search that extracts content from a file.

SELECT * FROM logs WHERE source = "%*SAP*%" and messages like "%,cn%" but do not get a search result.    *sap*  is part of the filename.     ,cn is part of the content...      any good ideas out there ??    

thanks.

helmut. 

Labels (1)
0 Karma
1 Solution

Mohammed_Rayan
Contributor

Helmut,

can you let us know what's the error you are facing while running that query. Maybe, you can share a screenshot if possible.

Also, I would suggest you to try something like below and let me know if it works and also try once without any wildcard charcters and share its result.

SELECT * FROM logs WHERE source = "%*SAP*%" and message ="%,cn%"

Regards,

Mohammed Rayan

View solution in original post

0 Karma

Mohammed_Rayan
Contributor

Helmut,

can you let us know what's the error you are facing while running that query. Maybe, you can share a screenshot if possible.

Also, I would suggest you to try something like below and let me know if it works and also try once without any wildcard charcters and share its result.

SELECT * FROM logs WHERE source = "%*SAP*%" and message ="%,cn%"

Regards,

Mohammed Rayan

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...