<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I use the contents of a log in a script triggered by an alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-I-use-the-contents-of-a-log-in-a-script-triggered-by-an/m-p/186453#M3115</link>
    <description>&lt;P&gt;Yes it,&lt;BR /&gt;
You need to use the alert parameters for the script. The search needs to be formatted so that you get the content in the field to use in the script. Pass the script in savedsearch window or &lt;CODE&gt;action.script.filename = &amp;lt;script filename&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;More documentation here:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Alert/Setupalertactions" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/Alert/Setupalertactions&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system" target="test_blank"&gt;https://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Community:TroubleshootingAlertScripts" target="test_blank"&gt;http://wiki.splunk.com/Community:TroubleshootingAlertScripts&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 13 Mar 2014 17:46:14 GMT</pubDate>
    <dc:creator>linu1988</dc:creator>
    <dc:date>2014-03-13T17:46:14Z</dc:date>
    <item>
      <title>How do I use the contents of a log in a script triggered by an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-use-the-contents-of-a-log-in-a-script-triggered-by-an/m-p/186452#M3114</link>
      <description>&lt;P&gt;I have a realtime alert that's kicking off a python script, and I'd like to use the contents of the log entry that triggered the alert in the script. Is that possible?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 16:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-use-the-contents-of-a-log-in-a-script-triggered-by-an/m-p/186452#M3114</guid>
      <dc:creator>treydismukes</dc:creator>
      <dc:date>2014-03-13T16:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use the contents of a log in a script triggered by an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-use-the-contents-of-a-log-in-a-script-triggered-by-an/m-p/186453#M3115</link>
      <description>&lt;P&gt;Yes it,&lt;BR /&gt;
You need to use the alert parameters for the script. The search needs to be formatted so that you get the content in the field to use in the script. Pass the script in savedsearch window or &lt;CODE&gt;action.script.filename = &amp;lt;script filename&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;More documentation here:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Alert/Setupalertactions" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/Alert/Setupalertactions&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system" target="test_blank"&gt;https://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Community:TroubleshootingAlertScripts" target="test_blank"&gt;http://wiki.splunk.com/Community:TroubleshootingAlertScripts&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 17:46:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-use-the-contents-of-a-log-in-a-script-triggered-by-an/m-p/186453#M3115</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-03-13T17:46:14Z</dc:date>
    </item>
  </channel>
</rss>

