<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic help with execution python as alert action needed in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/help-with-execution-python-as-alert-action-needed/m-p/431379#M12588</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Could someone please in short points describe what needs to be done in order to execute the python script as an alert action?&lt;BR /&gt;
In the simplest possible version the python would just trigger my savedsearch.&lt;BR /&gt;
How would it have to look like in the conf files and how the python itself needs to look like for that?&lt;/P&gt;

&lt;P&gt;.. I need to kick off my savedsearch as the follow up of the alert and have issues with this. I came to the idea to do this out of the python but I do not know what all configuration needs to be done for that and how the python would look like ...&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Kind Regards,&lt;BR /&gt;
Kamil&lt;/P&gt;</description>
    <pubDate>Fri, 02 Aug 2019 15:36:06 GMT</pubDate>
    <dc:creator>damucka</dc:creator>
    <dc:date>2019-08-02T15:36:06Z</dc:date>
    <item>
      <title>help with execution python as alert action needed</title>
      <link>https://community.splunk.com/t5/Alerting/help-with-execution-python-as-alert-action-needed/m-p/431379#M12588</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Could someone please in short points describe what needs to be done in order to execute the python script as an alert action?&lt;BR /&gt;
In the simplest possible version the python would just trigger my savedsearch.&lt;BR /&gt;
How would it have to look like in the conf files and how the python itself needs to look like for that?&lt;/P&gt;

&lt;P&gt;.. I need to kick off my savedsearch as the follow up of the alert and have issues with this. I came to the idea to do this out of the python but I do not know what all configuration needs to be done for that and how the python would look like ...&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Kind Regards,&lt;BR /&gt;
Kamil&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 15:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-with-execution-python-as-alert-action-needed/m-p/431379#M12588</guid>
      <dc:creator>damucka</dc:creator>
      <dc:date>2019-08-02T15:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: help with execution python as alert action needed</title>
      <link>https://community.splunk.com/t5/Alerting/help-with-execution-python-as-alert-action-needed/m-p/431380#M12589</link>
      <description>&lt;P&gt;I'm guessing you're referring to the "splunk search" alert action from the other question I'm helping you with? If so, just put the python script in the &lt;CODE&gt;bin&lt;/CODE&gt; dir inside the alert action. &lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 16:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/help-with-execution-python-as-alert-action-needed/m-p/431380#M12589</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-08-02T16:44:11Z</dc:date>
    </item>
  </channel>
</rss>

