Solved

How do I monitor a folder and email changes once a day?

Posted on 2016-08-15
12
79 Views
Last Modified: 2016-08-23
I have three different folders I need to monitor on a server. One for new folders and files added, one for files removed or deleted, and the other directory for files that have changed or been modified. I need a separate email sent to specified email addresses for each directory once a day, at a specified time, and its content will list the folders and files that have been added, modified, or deleted.  I have tried folder spy but it sends emails for every single change and that’s just too many emails.  Would prefer a PowerShell script that I could run as a scheduled task but at this point anything that will work I am interested in. Can anyone help?
0
Comment
Question by:wbrandle
  • 4
  • 4
  • 3
  • +1
12 Comments
 
LVL 12

Expert Comment

by:Dustin Saunders
Comment Utility
You have 2 ways to do this, depending on how you want to go about it.

Option 1 is to record all the files in the folder into a CSV or equivalent and then the scheduled task will compare what changed and send out an email.  This doesn't require a running service, etc.

The other option is to create a file system watcher in a dummy service and have that record the changes.

Do you need to see every time the files change or just a list of new, deleted, changed files?
1
 

Author Comment

by:wbrandle
Comment Utility
Just a new list. Basically, what has changed since the last email was sent out. I need the task done automatically so it does not become another added daily task.  The first directory is basically and "Inbox" for a specific group of employees to copy their completed work too. Then another specific group would get notified that there are files waiting for them so they could move the file out to another location.
The other two locations are just for monitoring sensitive restrictive directories.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
I would go the "compare to snapshot" way. The only issue is that you need to create the first snapshot manually.

Alternatively, you can trust to the archive bit (but need to reset it after processing to make it work) for added or changed files.
For deleted files you'll always need a reference, if not using a trigger (file system watcher).
0
 
LVL 12

Assisted Solution

by:Dustin Saunders
Dustin Saunders earned 250 total points
Comment Utility
The first approach I mentioned would look something like this (didn't get a chance to test it) but you'd need to compile this into a service with PowerGUI.  You can have functions fire when the file changes are done, so for example if a user makes a new file and it has the word 'invoice' in it, you get an email alert right away.  Otherwise it could just log the change and then send in the email later on.  It'd look like this:
$folder = 'c:\test\'
$filter = '*.*'
$logFolder = 'c:\log\'
$smtpServer = '192.168.1.1'
$smtpFrom = 'technotices@yourcompany.com'
$smtpTo = 'support@yourcompany.com'

$fsw = New-Object IO.FileSystemWatcher $folder, $filter -Property @{IncludeSubdirectories = $false;NotifyFilter = [IO.NotifyFilters]'FileName, LastWrite'} 

function GetLogFile
{
    $date = Get-Date
    $logFile = $logFolder + $date.Month + "-" + $date.Day + "-fileChange.log"
    return $logFile
}

function RecordMessage ($message)
{
    $logFile = GetLogFile
    Add-Content -Path $logFile -Value $message
}

function SendLogEmail
{
    $logFile = GetLogFile
    $subject = "Log File for " + $date
    Send-MailMessage -SmtpServer $smtpServer -From $smtpFrom -To $smtpTo -Attachments $logFile -Subject $subject -Body "Log file attached."
}

Register-ObjectEvent $fsw Created -SourceIdentifier FileCreated -Action { 
    $name = $folder + $Event.SourceEventArgs.Name 
    $changeType = $Event.SourceEventArgs.ChangeType 
    $timeStamp = $Event.TimeGenerated 
    $message = $name + " was " + $changeType + " at " + $timestamp + "."
    RecordMessage $message
} 

Register-ObjectEvent $fsw Deleted -SourceIdentifier FileDeleted -Action { 
    $name = $folder + $Event.SourceEventArgs.Name 
    $changeType = $Event.SourceEventArgs.ChangeType 
    $timeStamp = $Event.TimeGenerated 
    $message = $name + " was " + $changeType + " at " + $timestamp + "."
    RecordMessage $message
} 

Register-ObjectEvent $fsw Changed -SourceIdentifier FileChanged -Action { 
    $name = $folder + $Event.SourceEventArgs.Name 
    $changeType = $Event.SourceEventArgs.ChangeType 
    $timeStamp = $Event.TimeGenerated 
    $message = $name + " was " + $changeType + " at " + $timestamp + "."
    RecordMessage $message
} 

while($true)
{
    $time = Get-Date
    if ($time.Hour -eq 23 -and $time.Minute -eq 59 -and $time.Second -eq 58) {SendLogEmail}
    Start-Sleep -Seconds 1
}

Open in new window

1
 
LVL 12

Expert Comment

by:Dustin Saunders
Comment Utility
To do it with a "snapshot" file, I'd recommend loading those CSVs into datatables, then doing a compare there to generate the differences.  This EE answer from another question shows how I'd do the datatable compares:
foreach ($row in $dt1.Rows)
{
    $sqlRow = $dt2.Select("ID="+$row.ID)
    if ($sqlRow.Length -ne 0)
    {
        Write-Host "Update action."
    }
    else
    {
        Write-Host "Insert action."
    }
}

foreach ($row in $dt2.Rows)
{
    $compareRow = $dt1.Select("ID="+$row.ID)
    if ($compareRow.Length -eq 0)
    {
        Write-Host "Remove Action."
    }
}

Open in new window

0
 
LVL 68

Accepted Solution

by:
Qlemo earned 250 total points
Comment Utility
Assuming PowerShell 3.0 or above, a simplified approach is:
$smtpParam = @{
  SmtpServer = 'mail.domain.com'
  from       = 'me@domain.com'
  to         = 'you@domain.com'
}


foreach ($folder in 'C:\Monitoring\Folder1', 'C:\Monitoring\Folder2')
{
  $del = $new = $chg = $null
  $snapshot_file = 'C:\Monitoring\'+(split-path $folder -leaf)+'-files.txt'
  if (test-path $snapshot_file)
  {
    $snapshot_old = Get-Content $snapshot_file
    $snapshot_new = Get-ChildItem -recurse $folder -Name
    $cmp = compare-object $snapshot_old $snapshot_new
    $new = ($cmp | ? { $_.SideIndicator -eq '=>' }).InputObject
    $del = ($cmp | ? { $_.SideIndicator -eq '<=' }).InputObject

    $snapshot_date = (Get-ChildItem $snapshot_file).LastWriteTime
    $chg = Get-ChildItem -recurse $folder | ? { $_.LastWriteTime -gt $snapshot_date } | Select -Expand Name
  }

  if ($new) { Send-MailMessage @smtpParam -Subject "$folder - new files"     -Body ($new -join "`r`n") }
  if ($del) { Send-MailMessage @smtpParam -Subject "$folder - deleted files" -Body ($del -join "`r`n") }
  if ($chg) { Send-MailMessage @smtpParam -Subject "$folder - changed files" -Body ($chg -join "`r`n") }

  $snapshot_new | Out-File $snapshot_file
}

Open in new window

This treats all folders the same, and does not differ to whom mails are to send.
1
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 3

Expert Comment

by:Shabbir Rao
Comment Utility
0
 

Author Comment

by:wbrandle
Comment Utility
That's a lot of information, I will experiment with provided input thus far and get back to you a little later. Thanks All.
0
 

Author Comment

by:wbrandle
Comment Utility
So to be up front, I am not a PowerShell guy so please bare with me.
So I tried Qlemo's first. I copied everything into PowerShell ISE. I created a folder on my C: drive called Monitoring with two subfolders Folder1 & Folder2.  I changed the Smtp server information to an actual server and account. Rand the script and I get;

Compare-Object : Cannot bind argument to parameter 'ReferenceObject' because it is null.
At C:\Users\Employee\Documents\FolderMonitor.ps1:16 char:27
+     $cmp = compare-object $snapshot_old $snapshot_new
+                           ~~~~~~~~~~~~~
    + CategoryInfo          : InvalidData: (:) [Compare-Object], ParameterBindingValidationExcept
   ion
    + FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,Microsoft.PowerShell
   .Commands.CompareObjectCommand
 
Compare-Object : Cannot bind argument to parameter 'ReferenceObject' because it is null.
At C:\Users\Employee\Documents\FolderMonitor.ps1:16 char:27
+     $cmp = compare-object $snapshot_old $snapshot_new
+                           ~~~~~~~~~~~~~
    + CategoryInfo          : InvalidData: (:) [Compare-Object], ParameterBindingValidationExcept
   ion
    + FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,Microsoft.PowerShell
   .Commands.CompareObjectCommand

Was there something else I should have changed?

I will try Dustin's now. Thanks all.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
The error message means that the snapshot file has been found, but was empty. And indeed, I forgot to create the initial file content :/.
$smtpParam = @{
  SmtpServer = 'mail.domain.com'
  from       = 'me@domain.com'
  to         = 'you@domain.com'
}


foreach ($folder in 'C:\Monitoring\Folder1', 'C:\Monitoring\Folder2')
{
  $del = $new = $chg = $null
  $snapshot_file = 'C:\Monitoring\'+(split-path $folder -leaf)+'-files.txt'
  $snapshot_new = Get-ChildItem -recurse $folder -Name

  if (test-path $snapshot_file)
  {
    $snapshot_old = Get-Content $snapshot_file
    $cmp = compare-object $snapshot_old $snapshot_new
    $new = ($cmp | ? { $_.SideIndicator -eq '=>' }).InputObject
    $del = ($cmp | ? { $_.SideIndicator -eq '<=' }).InputObject

    $snapshot_date = (Get-ChildItem $snapshot_file).LastWriteTime
    $chg = Get-ChildItem -recurse $folder | ? { $_.LastWriteTime -gt $snapshot_date } | Select -Expand Name
  }

  if ($new) { Send-MailMessage @smtpParam -Subject "$folder - new files"     -Body ($new -join "`r`n") }
  if ($del) { Send-MailMessage @smtpParam -Subject "$folder - deleted files" -Body ($del -join "`r`n") }
  if ($chg) { Send-MailMessage @smtpParam -Subject "$folder - changed files" -Body ($chg -join "`r`n") }

  $snapshot_new | Out-File $snapshot_file
}

Open in new window

1
 

Author Comment

by:wbrandle
Comment Utility
Qlemo, could you provide how I would change the first part to include port and authentication?

$smtpParam = @{
  SmtpServer = 'mail.domain.com'
  from       = 'me@domain.com'
  to         = 'you@domain.com'
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
Authentication is usually not required if inside of your domain. It needs some more effort:
$smtpParam = @{
  SmtpServer = 'mail.domain.com'
  credential = New-Object System.Management.Automation.PsCredential('MyUser', (ConvertTo-SecureString 'MyPwd' -AsPlainText –force))
  Port       = 65432
  from       = 'me@domain.com'
  to         = 'you@domain.com'
}

Open in new window

You'll have to replace 'MyUser' and 'MyPwd', and of course the port number, by the real-life data.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
This article explains how to prepare an HTML email signature template file containing dynamic placeholders for users' Azure AD data. Furthermore, it explains how to use this file to remotely set up a department-wide email signature policy in Office …
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now