Alerting

Are There "Advanced" Alerts That Support Tokens for Dynamic Inputs?

niall_munnelly
Path Finder

The closest question I came to is this one, but it's not quite there (and it's old).

I have a saved search - actually an alert, with actions - that I want to pass dynamic SPL into. You can do this with dashboards and tokens, of course, but I'm specifically looking for an alert that I'm executing over the API.

So I may request something like this over the API:

https://splunk.mycompany.com:8089/en-US/app/myApp/search?s=%2FservicesNS%2Fnobody%2FmyApp%2Fsaved%2F...

Where the saved search has something like "Execution_ID=$ExecID$" in it - just like you would when requesting a dashboard. The value for $ExecID$ is unique and populating a lookup table for this simple need seems like serious overkill - and it probab;y doesn't even accomplish what I need.

I hope this is written clearly enough. I'm 99% sure it can't be done, but it's been a few years since that last question, and, as noted, it's not really a match, anyway. Thanks.

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...