Change or Removal of system log contents


How to write a json script if anyone change or Removal of system log contents.

can you please be more specific with your requirements (and not cross post or create new posts).
How are you logging your 'removal of system log contents' into elasticsearch? Can you query this state? If so, you can create a watch, but watcher is not a file system monitoring system.


