<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How To Restart A Windows-based Service From A Triggered Alert - Run A Script in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-To-Restart-A-Windows-based-Service-From-A-Triggered-Alert/m-p/387160#M69440</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have created a Splunk alert that will be triggered when a Windows-based service is down (ie. Print Spooler). For example, it will check a list of servers real-time and display the server/host if the Print Spooler service is down. My question is how do I automatically restart that Windows &amp;gt; Print Spooler service using the "Run a script" action from the alert? Do I need to create a batch script and put in the "$SPLUNK_HOME/bin/scripts" folder? Our Splunk search heads/indexer are running on Linux.&lt;/P&gt;

&lt;P&gt;Can someone help with an example on what the script should look like? Do I just create a simple batch script with the following line... &lt;/P&gt;

&lt;P&gt;sc.exe start "Print Spooler"&lt;/P&gt;

&lt;P&gt;Also, do I need to pass the $result.host$ to the script so that it knows which server/host to run the script?&lt;/P&gt;

&lt;P&gt;Thank you for your advice.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2018 16:14:01 GMT</pubDate>
    <dc:creator>bennykhoo</dc:creator>
    <dc:date>2018-11-16T16:14:01Z</dc:date>
    <item>
      <title>How To Restart A Windows-based Service From A Triggered Alert - Run A Script</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-To-Restart-A-Windows-based-Service-From-A-Triggered-Alert/m-p/387160#M69440</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have created a Splunk alert that will be triggered when a Windows-based service is down (ie. Print Spooler). For example, it will check a list of servers real-time and display the server/host if the Print Spooler service is down. My question is how do I automatically restart that Windows &amp;gt; Print Spooler service using the "Run a script" action from the alert? Do I need to create a batch script and put in the "$SPLUNK_HOME/bin/scripts" folder? Our Splunk search heads/indexer are running on Linux.&lt;/P&gt;

&lt;P&gt;Can someone help with an example on what the script should look like? Do I just create a simple batch script with the following line... &lt;/P&gt;

&lt;P&gt;sc.exe start "Print Spooler"&lt;/P&gt;

&lt;P&gt;Also, do I need to pass the $result.host$ to the script so that it knows which server/host to run the script?&lt;/P&gt;

&lt;P&gt;Thank you for your advice.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 16:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-To-Restart-A-Windows-based-Service-From-A-Triggered-Alert/m-p/387160#M69440</guid>
      <dc:creator>bennykhoo</dc:creator>
      <dc:date>2018-11-16T16:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: How To Restart A Windows-based Service From A Triggered Alert - Run A Script</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-To-Restart-A-Windows-based-Service-From-A-Triggered-Alert/m-p/387161#M69441</link>
      <description>&lt;P&gt;I'd like to know the same thing.  I've been trying to do something very similar for about 6 months and read every document splunk has and nothing seems to work.  &lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 17:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-To-Restart-A-Windows-based-Service-From-A-Triggered-Alert/m-p/387161#M69441</guid>
      <dc:creator>sals1648</dc:creator>
      <dc:date>2019-04-04T17:36:05Z</dc:date>
    </item>
  </channel>
</rss>

