<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Any ways to configure Alert actions to syslog server? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653693#M15252</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259468"&gt;@kn-nowit&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No I used again this app even if isn't certified.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2023 07:36:13 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-08-09T07:36:13Z</dc:date>
    <item>
      <title>How to configure Alert actions to syslog server?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/611592#M14209</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I am using Splunk Enterprise 8.1.&lt;/P&gt;
&lt;P&gt;Recently, we had configured&amp;nbsp;alert actions as "Email notification action" and it works fine. Moreover, we would like to send those alert message to SYSLOG server.&lt;/P&gt;
&lt;P&gt;The manual said "script alert action is deprecated". Any other way to&amp;nbsp;achieve it?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 16:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/611592#M14209</guid>
      <dc:creator>alexshek</dc:creator>
      <dc:date>2023-08-09T16:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Any ways to configure Alert actions to syslog server?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/611593#M14210</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249084"&gt;@alexshek&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some time ago (on version 8.1), I used the Syslog Modular Alert App (&lt;A href="https://splunkbase.splunk.com/app/4199/)" target="_blank"&gt;https://splunkbase.splunk.com/app/4199/)&lt;/A&gt;&amp;nbsp;but it isn't certified on version 9.x, you could try if it runs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 10:47:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/611593#M14210</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-01T10:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Any ways to configure Alert actions to syslog server?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653558#M15249</link>
      <description>&lt;P&gt;Did you find a nice solution in the meantime?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 10:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653558#M15249</guid>
      <dc:creator>kn-nowit</dc:creator>
      <dc:date>2023-08-08T10:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Any ways to configure Alert actions to syslog server?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653693#M15252</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259468"&gt;@kn-nowit&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No I used again this app even if isn't certified.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 07:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653693#M15252</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-09T07:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Any ways to configure Alert actions to syslog server?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653967#M15264</link>
      <description>&lt;P&gt;Thanks for your info!&lt;/P&gt;&lt;P&gt;We didn't get it to work in our platform which runs in version 9.0.5&lt;/P&gt;&lt;P&gt;But we've found another app with the same features which works for us!&lt;BR /&gt;Syslog alert action Add-On&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/6177" target="_blank"&gt;https://splunkbase.splunk.com/app/6177&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's really easy to use in Alerts or as Adaptive Response Action in Splunk ES.&lt;BR /&gt;Create your customized syslog-message using &lt;FONT face="courier new,courier"&gt;eval syslogmessage = ..&lt;/FONT&gt; in the Search query and mention the syslogmessage field als message param in the app config.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="searchquery.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26751iC908D48E0998E2F3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="searchquery.PNG" alt="searchquery.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="action.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26750iFF58C98517D89419/image-size/medium?v=v2&amp;amp;px=400" role="button" title="action.PNG" alt="action.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 15:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-configure-Alert-actions-to-syslog-server/m-p/653967#M15264</guid>
      <dc:creator>kn-nowit</dc:creator>
      <dc:date>2023-08-10T15:50:20Z</dc:date>
    </item>
  </channel>
</rss>

