Alerting

Create an email alert when a notable event is get assigned to a new User.

vikajha
Explorer

Is there a way to send email alert to a user who got assigned a notable event to themselves from ES incident review tab . This should only fire if user other then owner is assigning a notable event to them. For example if user A has assigned a notable event to User B then a email alert should sent to User B but not in case when User B assign an event to himself. This alert should not fire if User A add a comment to notable event assigned to User B as I have checked one answer but that is also triggering alert when a comment is being added . EX
| incident_review | where owner_realname="GT3 Analyst" AND owner_realname != reviewer_realname AND _time>=relative_time(now(),"-40m") AND _time

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...