Need a query to check number file renames within a second.

Comments

6 comments

  • Avatar
    Nick Wilson

    Hi Dungar,

    For your first question (counting when a file gets renamed) could you please provide us some insight into what your data looks like? What type of source are you trying to query? Are these OS event logs, or some custom application? Would you be able to provide any samples of what this even looks like in the logs?

    For your second question (monitoring files with particular extensions), it would depend exactly what you're trying to monitor with those extensions. Do you just need to be alerted whenever those extensions show up in a log line? Is the filename/extension something you're already parsing with a field extraction rule?

    Thanks,
    Nick
    Customer Success, Sumo Logic

    0
    Comment actions Permalink
  • Avatar
    Dungar Rathod

    Hi Nick,

     

    Thanks for your reply.

    1) I am looking forward to apache logs as well as windows event logs. I need count of files renamed for particular interval of time.

     

    2)I am just thinking if this possible to monitor / create a dashboard  for above file extensions. only if above file extension are matched then only entry should showed into dashboard or logs.

     

    Let me know if you need more information.

    0
    Comment actions Permalink
  • Avatar
    Nick Wilson

    Hi Dungar,

    For 1) I'm not sure I understand what the files that are being renamed would show up in your Apache logs. Could you elaborate on what files you're referring to? For Windows, I believe there are event logs to help identify this, but I'll have to do a little more research and get back to you.

    For 2) this depends on your log sources that contain these extensions. Is this coming from a custom app log or something else?

     

    Thanks!
    Nick
    Customer Success, Sumo Logic

    0
    Comment actions Permalink
  • Avatar
    Dungar Rathod

    lets try to build query for windows for both questions if possible.

    0
    Comment actions Permalink
  • Avatar
    Dungar Rathod

    Hi Nick,

     

    Any update?
    Thanks

    0
    Comment actions Permalink
  • Avatar
    Nick Wilson

    Hi Dungar,

    I'm so sorry for the delay here. I just sent you an email separately to get a little more information about your particular collectors so that I can help you out further.

    I'll post back here once we have a solution for everyone else's benefit.

    Thanks,
    Nick
    Customer Success, Sumo Logic

    0
    Comment actions Permalink

Please sign in to leave a comment.