<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to - Custom alert action (passing arguments to custom scripts) in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440088#M11834</link>
    <description>&lt;P&gt;If you want to use a custom script in alert actions and pass arguments to it when the alert is triggered&lt;/P&gt;

&lt;P&gt;Let us assume a sample.sh script as below which will accept a name a argument and print to a sample.log file&lt;/P&gt;

&lt;P&gt;!/bin/bash&lt;BR /&gt;
echo "hello $1 @ date +%Y-%m-%d-%H:%M:%S" &amp;gt;&amp;gt; /path/sample.log&lt;BR /&gt;
exit 0&lt;/P&gt;

&lt;P&gt;We need to do the following to use this script in alert actions&lt;/P&gt;

&lt;P&gt;Create an app "MyApp" with a "bin" directory and "default" directory&lt;/P&gt;

&lt;P&gt;Place the sample.sh and another file .path file. The .path file should have the location of the executable.&lt;/P&gt;

&lt;P&gt;In this example, we are creating a bash.path with "/bin/bash" as its contents.&lt;/P&gt;

&lt;P&gt;In the default directory, create app.conf and alert_actions.conf.&lt;/P&gt;

&lt;P&gt;app.conf&lt;/P&gt;

&lt;P&gt;[launcher]&lt;BR /&gt;
version = 1.0&lt;/P&gt;

&lt;P&gt;[ui]&lt;BR /&gt;
is_visible = false&lt;BR /&gt;
label = Splunk Custom Alert Example&lt;/P&gt;

&lt;P&gt;alert_actions.conf&lt;/P&gt;

&lt;P&gt;[custom_script]&lt;/P&gt;

&lt;H1&gt;flag the action as custom alert action&lt;/H1&gt;

&lt;P&gt;is_custom = 1&lt;/P&gt;

&lt;P&gt;configure appearance in the UI&lt;BR /&gt;
label = Custom Script Alert Action&lt;BR /&gt;
description = Triggers a custom alert action&lt;BR /&gt;
icon_path = custom_alert.png&lt;/P&gt;

&lt;P&gt;override default script execution&lt;BR /&gt;
alert.execute.cmd = bash.path&lt;BR /&gt;
alert.execute.cmd.arg.1 = /opt/splunk/etc/apps/myapp/bin/sample.sh&lt;BR /&gt;
alert.execute.cmd.arg.2 = Anyname&lt;/P&gt;

&lt;P&gt;After splunk restart, a custom alert action will be created, which needs to be selected during the alert creation.&lt;/P&gt;

&lt;P&gt;In the alert_actions.conf you can pass any number of arguments to your script.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:02:41 GMT</pubDate>
    <dc:creator>mbagali_splunk</dc:creator>
    <dc:date>2020-09-29T23:02:41Z</dc:date>
    <item>
      <title>How to - Custom alert action (passing arguments to custom scripts)</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440086#M11832</link>
      <description>&lt;P&gt;How  to use a custom script in alert actions and pass arguments to it when the alert is triggered&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 12:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440086#M11832</guid>
      <dc:creator>mbagali_splunk</dc:creator>
      <dc:date>2019-01-31T12:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to - Custom alert action (passing arguments to custom scripts)</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440087#M11833</link>
      <description>&lt;P&gt;If you want to use a custom script in alert actions and pass arguments to it when the alert is triggered&lt;/P&gt;

&lt;P&gt;Let us assume a sample.sh script as below which will accept a name a argument and print to a sample.log file&lt;/P&gt;

&lt;H1&gt;!/bin/bash&lt;/H1&gt;

&lt;P&gt;echo "hello $1 @ &lt;CODE&gt;date +%Y-%m-%d-%H:%M:%S&lt;/CODE&gt;" &amp;gt;&amp;gt; /path/sample.log&lt;BR /&gt;
exit 0&lt;/P&gt;

&lt;P&gt;We need to do the following to use this script in alert actions&lt;/P&gt;

&lt;P&gt;Create an app "MyApp" with a "bin" directory and "default" directory&lt;/P&gt;

&lt;P&gt;Place the sample.sh and another file .path file. The .path file should have the location of the executable.&lt;/P&gt;

&lt;P&gt;In this example, we are creating a bash.path with "/bin/bash" as its contents.&lt;/P&gt;

&lt;P&gt;In the default directory, create app.conf and alert_actions.conf.&lt;/P&gt;

&lt;P&gt;app.conf&lt;/P&gt;

&lt;P&gt;[launcher]&lt;BR /&gt;
version = 1.0&lt;/P&gt;

&lt;P&gt;[ui]&lt;BR /&gt;
is_visible = false&lt;BR /&gt;
label = Splunk Custom Alert Example&lt;/P&gt;

&lt;P&gt;alert_actions.conf&lt;/P&gt;

&lt;P&gt;[custom_script]&lt;/P&gt;

&lt;H1&gt;flag the action as custom alert action&lt;/H1&gt;

&lt;P&gt;is_custom = 1&lt;/P&gt;

&lt;H1&gt;configure appearance in the UI&lt;/H1&gt;

&lt;P&gt;label = Custom Script Alert Action&lt;BR /&gt;
description = Triggers a custom alert action&lt;BR /&gt;
icon_path = custom_alert.png&lt;/P&gt;

&lt;H1&gt;override default script execution&lt;/H1&gt;

&lt;P&gt;alert.execute.cmd =  bash.path&lt;BR /&gt;
alert.execute.cmd.arg.1 = /opt/splunk/etc/apps/myapp/bin/sample.sh&lt;BR /&gt;
alert.execute.cmd.arg.2 = Anyname&lt;/P&gt;

&lt;P&gt;After splunk restart, a custom alert action will be created, which needs to be selected during the alert creation.&lt;/P&gt;

&lt;P&gt;In the alert_actions.conf you can pass any number of arguments to your script.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440087#M11833</guid>
      <dc:creator>mbagali_splunk</dc:creator>
      <dc:date>2020-09-29T23:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to - Custom alert action (passing arguments to custom scripts)</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440088#M11834</link>
      <description>&lt;P&gt;If you want to use a custom script in alert actions and pass arguments to it when the alert is triggered&lt;/P&gt;

&lt;P&gt;Let us assume a sample.sh script as below which will accept a name a argument and print to a sample.log file&lt;/P&gt;

&lt;P&gt;!/bin/bash&lt;BR /&gt;
echo "hello $1 @ date +%Y-%m-%d-%H:%M:%S" &amp;gt;&amp;gt; /path/sample.log&lt;BR /&gt;
exit 0&lt;/P&gt;

&lt;P&gt;We need to do the following to use this script in alert actions&lt;/P&gt;

&lt;P&gt;Create an app "MyApp" with a "bin" directory and "default" directory&lt;/P&gt;

&lt;P&gt;Place the sample.sh and another file .path file. The .path file should have the location of the executable.&lt;/P&gt;

&lt;P&gt;In this example, we are creating a bash.path with "/bin/bash" as its contents.&lt;/P&gt;

&lt;P&gt;In the default directory, create app.conf and alert_actions.conf.&lt;/P&gt;

&lt;P&gt;app.conf&lt;/P&gt;

&lt;P&gt;[launcher]&lt;BR /&gt;
version = 1.0&lt;/P&gt;

&lt;P&gt;[ui]&lt;BR /&gt;
is_visible = false&lt;BR /&gt;
label = Splunk Custom Alert Example&lt;/P&gt;

&lt;P&gt;alert_actions.conf&lt;/P&gt;

&lt;P&gt;[custom_script]&lt;/P&gt;

&lt;H1&gt;flag the action as custom alert action&lt;/H1&gt;

&lt;P&gt;is_custom = 1&lt;/P&gt;

&lt;P&gt;configure appearance in the UI&lt;BR /&gt;
label = Custom Script Alert Action&lt;BR /&gt;
description = Triggers a custom alert action&lt;BR /&gt;
icon_path = custom_alert.png&lt;/P&gt;

&lt;P&gt;override default script execution&lt;BR /&gt;
alert.execute.cmd = bash.path&lt;BR /&gt;
alert.execute.cmd.arg.1 = /opt/splunk/etc/apps/myapp/bin/sample.sh&lt;BR /&gt;
alert.execute.cmd.arg.2 = Anyname&lt;/P&gt;

&lt;P&gt;After splunk restart, a custom alert action will be created, which needs to be selected during the alert creation.&lt;/P&gt;

&lt;P&gt;In the alert_actions.conf you can pass any number of arguments to your script.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440088#M11834</guid>
      <dc:creator>mbagali_splunk</dc:creator>
      <dc:date>2020-09-29T23:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to - Custom alert action (passing arguments to custom scripts)</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440089#M11835</link>
      <description>&lt;P&gt;If you just name your script &lt;CODE&gt;custom_script.sh&lt;/CODE&gt; - using exactly the phrase from the corresponding &lt;CODE&gt;alerts_action.conf&lt;/CODE&gt; stanza, the &lt;CODE&gt;bash.path&lt;/CODE&gt; file and the &lt;CODE&gt;alert.execute.*&lt;/CODE&gt; entries in &lt;CODE&gt;alert_actions.conf&lt;/CODE&gt; are not necessary.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 10:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-Custom-alert-action-passing-arguments-to-custom-scripts/m-p/440089#M11835</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2019-05-03T10:18:43Z</dc:date>
    </item>
  </channel>
</rss>

