Alerting
Highlighted

How do I use the contents of a log in a script triggered by an alert?

Engager

I have a realtime alert that's kicking off a python script, and I'd like to use the contents of the log entry that triggered the alert in the script. Is that possible?

Tags (2)
0 Karma
Highlighted

Re: How do I use the contents of a log in a script triggered by an alert?

Champion

Yes it,
You need to use the alert parameters for the script. The search needs to be formatted so that you get the content in the field to use in the script. Pass the script in savedsearch window or action.script.filename = <script filename>

More documentation here:

http://docs.splunk.com/Documentation/Splunk/6.0.2/Alert/Setupalertactions
https://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketin...
http://wiki.splunk.com/Community:TroubleshootingAlertScripts

Thanks

0 Karma