<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding IP's to a exposed text file in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Adding-IP-s-to-a-exposed-text-file/m-p/550212#M10463</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/187331"&gt;@arunkuriakose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can add on your alert action an sh script to save all result ip on your txt file.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/AdvancedDev/CustomAlertScript" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/AdvancedDev/CustomAlertScript&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or if in your case works fine a csv file you can add on your alert search the outputlookup comand to save the results in a new csv file.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2021 09:55:14 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-05-03T09:55:14Z</dc:date>
    <item>
      <title>Adding IP's to a exposed text file</title>
      <link>https://community.splunk.com/t5/Alerting/Adding-IP-s-to-a-exposed-text-file/m-p/550203#M10462</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;I want to collect source ip from an alert triggered /search ran and then add that to a .txt file exposed on a separate server.(&lt;A href="https://urlofserver/ipfile.txt" target="_blank" rel="noopener"&gt;https://urlofserver/ipfile.txt&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to achieve this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 09:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Adding-IP-s-to-a-exposed-text-file/m-p/550203#M10462</guid>
      <dc:creator>arunkuriakose</dc:creator>
      <dc:date>2021-05-03T09:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adding IP's to a exposed text file</title>
      <link>https://community.splunk.com/t5/Alerting/Adding-IP-s-to-a-exposed-text-file/m-p/550212#M10463</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/187331"&gt;@arunkuriakose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can add on your alert action an sh script to save all result ip on your txt file.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/AdvancedDev/CustomAlertScript" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/AdvancedDev/CustomAlertScript&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or if in your case works fine a csv file you can add on your alert search the outputlookup comand to save the results in a new csv file.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 09:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Adding-IP-s-to-a-exposed-text-file/m-p/550212#M10463</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-03T09:55:14Z</dc:date>
    </item>
  </channel>
</rss>

