Hi,
I have a requirement. If a logfile is not created, then Splunk should alert the system.
How can we achieve this?
Thanks
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Have your alert search for events from the logfile in question. It should trigger if the number of events found is zero. You'll need to be careful about scheduling the search to allow for natural quiet periods in the log.
index=foo source=logfile
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @abhishekgandhe
Did the answer below solve your problem? If so, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help ya. Thanks for posting!
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Have your alert search for events from the logfile in question. It should trigger if the number of events found is zero. You'll need to be careful about scheduling the search to allow for natural quiet periods in the log.
index=foo source=logfile
I want to find whether logfile has 0 events in last 2 hrs. If it has 0 events, that's means no new logs are created in last 2 hrs. If 0 events, then I should alert the system.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		You've restated my answer. Does it work?
Thanks it worked
