<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic alert in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/alert/m-p/557456#M9238</link>
    <description>&lt;P&gt;Hello Members,&lt;/P&gt;&lt;P&gt;I have a requirement, in which i have 5 servers, in which i want to send and alert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In which five server are :&lt;/P&gt;&lt;P&gt;a, b,c,d,e,f&lt;/P&gt;&lt;P&gt;I want to set an alert in which when the CPU utilization is high on server a --- then alert send to one specific email id&amp;nbsp;@@abc.splunk.com&amp;nbsp; and for the other 4 servers i want to send an alert on email group&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;---xyz@splunk.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In splunk alert setting there is no option, we need to put through SPL by using the eval, but it is not working for me.&lt;/P&gt;&lt;P&gt;I have tried as below :&lt;/P&gt;&lt;P&gt;| eval condition_alert=if(server == "a", "abc.splunk.com", "&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;xyz@splunk.com&lt;/A&gt;") --- it is not working&lt;/P&gt;&lt;P&gt;| eval condition_alert=if(LIKE(server,"%a%"),"abc.splunk.com", "&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;xyz@splunk.com&lt;/A&gt;") --- it is also not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest me the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 16:24:44 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2021-06-28T16:24:44Z</dc:date>
    <item>
      <title>alert</title>
      <link>https://community.splunk.com/t5/Reporting/alert/m-p/557456#M9238</link>
      <description>&lt;P&gt;Hello Members,&lt;/P&gt;&lt;P&gt;I have a requirement, in which i have 5 servers, in which i want to send and alert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In which five server are :&lt;/P&gt;&lt;P&gt;a, b,c,d,e,f&lt;/P&gt;&lt;P&gt;I want to set an alert in which when the CPU utilization is high on server a --- then alert send to one specific email id&amp;nbsp;@@abc.splunk.com&amp;nbsp; and for the other 4 servers i want to send an alert on email group&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;---xyz@splunk.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In splunk alert setting there is no option, we need to put through SPL by using the eval, but it is not working for me.&lt;/P&gt;&lt;P&gt;I have tried as below :&lt;/P&gt;&lt;P&gt;| eval condition_alert=if(server == "a", "abc.splunk.com", "&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;xyz@splunk.com&lt;/A&gt;") --- it is not working&lt;/P&gt;&lt;P&gt;| eval condition_alert=if(LIKE(server,"%a%"),"abc.splunk.com", "&lt;A href="mailto:---xyz@splunk.com" target="_blank" rel="noopener"&gt;xyz@splunk.com&lt;/A&gt;") --- it is also not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest me the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 16:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/alert/m-p/557456#M9238</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2021-06-28T16:24:44Z</dc:date>
    </item>
  </channel>
</rss>

