<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I set up a script to run after an alert is triggered? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316635#M5651</link>
    <description>&lt;P&gt;A really quick and dirty method is to do this in Bash - if nothing else it will help you get to grips with how the process works.&lt;/P&gt;

&lt;P&gt;my_custom_action.sh&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#!/bin/bash
ResultsList=$(cat $8|gzip -d|tail -n +2)
echo $ResultsList &amp;gt; output.txt
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Taking each command as it comes:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;ResultsList&lt;/CODE&gt; will contain the results of your Splunk search&lt;BR /&gt;
&lt;CODE&gt;cat $8&lt;/CODE&gt; when splunk executes your script the $8 parameter will be the path of the search results on your server. Cat will output the contents of the file and pass it to:&lt;BR /&gt;
&lt;CODE&gt;gzip -d&lt;/CODE&gt; - this will decompress the results to make them readable, and then:&lt;BR /&gt;
&lt;CODE&gt;tail -n +2&lt;/CODE&gt; - will ignore the top line which is the header, and start reading from line 2!&lt;BR /&gt;
&lt;CODE&gt;echo $ResultsList&lt;/CODE&gt; will write the results of the above into output.txt for you to review.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:00:00 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2020-09-29T17:00:00Z</dc:date>
    <item>
      <title>How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316630#M5646</link>
      <description>&lt;P&gt;I want to run a script after a particular alert triggers, taking server names as input from the Splunk alert result.&lt;BR /&gt;
The alerts result is in bellow format:&lt;BR /&gt;
&lt;STRONG&gt;time   server  LoadFailed     date&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I want to take server list from here and execute a command on all the servers listed .&lt;/P&gt;

&lt;P&gt;I have gone through &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Alert/Configuringscriptedalerts"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Alert/Configuringscriptedalerts&lt;/A&gt; document , but couldn't implement much .&lt;BR /&gt;
Just could get a idea that may we we need to open file result and grep the argument .&lt;BR /&gt;
Please  help with the script.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
AD&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 07:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316630#M5646</guid>
      <dc:creator>DAnkita</dc:creator>
      <dc:date>2017-12-01T07:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316631#M5647</link>
      <description>&lt;P&gt;Hi @DAnkita,&lt;/P&gt;

&lt;P&gt;Which version of splunk version are you running ? Because Scripted Alerts are deprecated since Splunk 6.3 and this feature is replaced with &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/AdvancedDev/ModAlertsIntro"&gt;Custom Alert Action&lt;/A&gt; so I'll recommend you to create custom alert action based on your requirement if you are running Splunk Version 6.3 or higher. In given &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/AdvancedDev/ModAlertsIntro"&gt;Custom Alert Action&lt;/A&gt; link, splunk also provided 2-3 example so you refer those as well.&lt;/P&gt;

&lt;P&gt;I hope this helps.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harshil&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 08:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316631#M5647</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-01T08:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316632#M5648</link>
      <description>&lt;P&gt;Hi Harshil ,&lt;/P&gt;

&lt;P&gt;Thanks for your reply , I m using Splunkweb7 currently .&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 09:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316632#M5648</guid>
      <dc:creator>DAnkita</dc:creator>
      <dc:date>2017-12-01T09:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316633#M5649</link>
      <description>&lt;P&gt;My main problem is how can we take the server list as a input , if you can help .&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 09:31:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316633#M5649</guid>
      <dc:creator>DAnkita</dc:creator>
      <dc:date>2017-12-01T09:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316634#M5650</link>
      <description>&lt;P&gt;In Custom Alert action when you fetch &lt;CODE&gt;payload&lt;/CODE&gt;, you will able to see &lt;CODE&gt;results_file&lt;/CODE&gt; which generates when your schedule search will run and it will store output value in csv format but file will be in compressed &lt;CODE&gt;.gz&lt;/CODE&gt; format.&lt;/P&gt;

&lt;P&gt;So high level steps in your script for Custom Alert Action&lt;BR /&gt;
1.) Fetch &lt;CODE&gt;results_file&lt;/CODE&gt; from &lt;CODE&gt;payload&lt;/CODE&gt;&lt;BR /&gt;
2.) zcat &lt;CODE&gt;results_file&lt;/CODE&gt; and find count of rows without header and store it in variable&lt;BR /&gt;
3.) Run for loop with count which you found in Step 2 and read rows one by one and fetch server from that row value and do necessary action based on your requirement.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 09:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316634#M5650</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-01T09:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I set up a script to run after an alert is triggered?</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316635#M5651</link>
      <description>&lt;P&gt;A really quick and dirty method is to do this in Bash - if nothing else it will help you get to grips with how the process works.&lt;/P&gt;

&lt;P&gt;my_custom_action.sh&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#!/bin/bash
ResultsList=$(cat $8|gzip -d|tail -n +2)
echo $ResultsList &amp;gt; output.txt
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Taking each command as it comes:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;ResultsList&lt;/CODE&gt; will contain the results of your Splunk search&lt;BR /&gt;
&lt;CODE&gt;cat $8&lt;/CODE&gt; when splunk executes your script the $8 parameter will be the path of the search results on your server. Cat will output the contents of the file and pass it to:&lt;BR /&gt;
&lt;CODE&gt;gzip -d&lt;/CODE&gt; - this will decompress the results to make them readable, and then:&lt;BR /&gt;
&lt;CODE&gt;tail -n +2&lt;/CODE&gt; - will ignore the top line which is the header, and start reading from line 2!&lt;BR /&gt;
&lt;CODE&gt;echo $ResultsList&lt;/CODE&gt; will write the results of the above into output.txt for you to review.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-I-set-up-a-script-to-run-after-an-alert-is-triggered/m-p/316635#M5651</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-09-29T17:00:00Z</dc:date>
    </item>
  </channel>
</rss>

