Alerting

Change alert target email based on data

smileyge
Path Finder

I would like to set up an alert that sends an email to an email address contained in the data that the alert triggers on. For example, let's say I have a data set that contains emails, and I want to count those and send those email addresses their counts every week or on some other timing. Can I somehow pipe the email field from the data that generated the alert into the email that is sent, instead of specifying the alert emails should always go to a static address I specify at the time I configure the alert?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Splunk's alert emails can't do that out of the box. However, you can modify a copy of the sendemail command to roll your own email script that reads receivers from the data rather than from the alert config.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk's alert emails can't do that out of the box. However, you can modify a copy of the sendemail command to roll your own email script that reads receivers from the data rather than from the alert config.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Update: Splunk 6.1 comes with this very feature 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...