Splunk Search

alert when json data changes

gdavid
Path Finder

is there a way to alert when json data changes? 

i want to track changes for a variety of apis results/output that should stay static. i want to know when they change with an email. my thought is to daily grab the api data via powershell and post it to splunk via http collector or flat file input via forwarder.

is it possible to have splunk alert on change, and a plus would be providing the key/value pair that changed. 

 

thanks

Gd.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

In general, if you can search for it in Splunk then you can alert on it.  I suggest you create a test index and add your JSON data to it.  Then experiment with searches to find when data changes.  If you have problems with that, you can post new, specific questions.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...