<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cataloging Report Notification Actions in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540864#M153076</link>
    <description>&lt;P&gt;That worked PERFECTLY! Thank you for your help.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2021 16:08:25 GMT</pubDate>
    <dc:creator>deaseec</dc:creator>
    <dc:date>2021-02-22T16:08:25Z</dc:date>
    <item>
      <title>Cataloging Report Notification Actions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540446#M152898</link>
      <description>&lt;P&gt;I am looking to catalog which reports/alerts utilize which notification actions. I have a search currently that keys off of, "alert_action", but this is only effective IF the alert has already fired off in the specified time frame. However, I need to be able to see any alerts that will take a given action, even if they have not fired off. Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 21:59:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540446#M152898</guid>
      <dc:creator>deaseec</dc:creator>
      <dc:date>2021-02-18T21:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cataloging Report Notification Actions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540679#M152978</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231669"&gt;@deaseec&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can query searches and actions using the REST API.&lt;/P&gt;&lt;P&gt;| rest /servicesNS/-/-/saved/searches count=0 splunk_server=local&lt;BR /&gt;| foreach action.*&lt;BR /&gt;[| eval alert_actions=mvappend(alert_actions, case('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'==1 AND match("&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;", "^action\.[^.]+$"), "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"))]&lt;BR /&gt;| fields splunk_server eai:acl.app title author alert_actions&lt;BR /&gt;| search alert_actions=*&lt;/P&gt;&lt;P&gt;Actions have field names like action.foo.&lt;/P&gt;&lt;P&gt;Action parameters have field names like action.foo.bar.&lt;/P&gt;&lt;P&gt;In this example, I've used foreach to iterate over field names and add them to a multi-valued field named alert_actions if 1) the value is 1 and 2) the field is not a parameter.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 00:25:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540679#M152978</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2021-02-21T00:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cataloging Report Notification Actions</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540864#M153076</link>
      <description>&lt;P&gt;That worked PERFECTLY! Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 16:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cataloging-Report-Notification-Actions/m-p/540864#M153076</guid>
      <dc:creator>deaseec</dc:creator>
      <dc:date>2021-02-22T16:08:25Z</dc:date>
    </item>
  </channel>
</rss>

