<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Run a search based on alert result in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Run-a-search-based-on-alert-result/m-p/400490#M6897</link>
    <description>&lt;P&gt;First possibility - look at @woodcock's answer to this question of how do you prevent a search from running during blackout periods. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/24824/can-i-set-a-blackout-period-for-a-scheduled-search-during-which-it-should-not-generate-alerts.html"&gt;https://answers.splunk.com/answers/24824/can-i-set-a-blackout-period-for-a-scheduled-search-during-which-it-should-not-generate-alerts.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You could apply a version of that solution.&lt;/P&gt;

&lt;P&gt;Second possibility - you could use your first search to determine and return the &lt;CODE&gt;earliest=&lt;/CODE&gt; and &lt;CODE&gt;latest=&lt;/CODE&gt; times for your search that collects the data... and then set teh same arbitrary future date/time as both &lt;CODE&gt;earliest&lt;/CODE&gt; and &lt;CODE&gt;latest&lt;/CODE&gt; if your search determines there is no data. &lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 01:25:27 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2018-08-14T01:25:27Z</dc:date>
    <item>
      <title>Run a search based on alert result</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Run-a-search-based-on-alert-result/m-p/400489#M6896</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
i would like to run a search (to collect data in a summary index) triggered by an alert, which is checking for new data. e.g. if the start of a new dataset comes in, i would like to enrich, manipulate and collect the last dataset into a summary index.&lt;/P&gt;

&lt;P&gt;if the collect search only runs on a time schedule, i may get inconsistencies in between the collected dataset due to cutting in between. &lt;BR /&gt;
i'm looking for something like a custom alert action to trigger another saved search.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 12:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Run-a-search-based-on-alert-result/m-p/400489#M6896</guid>
      <dc:creator>maada</dc:creator>
      <dc:date>2018-08-13T12:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Run a search based on alert result</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Run-a-search-based-on-alert-result/m-p/400490#M6897</link>
      <description>&lt;P&gt;First possibility - look at @woodcock's answer to this question of how do you prevent a search from running during blackout periods. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/24824/can-i-set-a-blackout-period-for-a-scheduled-search-during-which-it-should-not-generate-alerts.html"&gt;https://answers.splunk.com/answers/24824/can-i-set-a-blackout-period-for-a-scheduled-search-during-which-it-should-not-generate-alerts.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You could apply a version of that solution.&lt;/P&gt;

&lt;P&gt;Second possibility - you could use your first search to determine and return the &lt;CODE&gt;earliest=&lt;/CODE&gt; and &lt;CODE&gt;latest=&lt;/CODE&gt; times for your search that collects the data... and then set teh same arbitrary future date/time as both &lt;CODE&gt;earliest&lt;/CODE&gt; and &lt;CODE&gt;latest&lt;/CODE&gt; if your search determines there is no data. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 01:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Run-a-search-based-on-alert-result/m-p/400490#M6897</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-14T01:25:27Z</dc:date>
    </item>
  </channel>
</rss>

