Alerting

How do you dynamically send an email notification to multiple recipients based on the search output?

isamrat
Explorer

I have one alert stanza in my savedsearches.conf. Now, I want to dynamically send email notifications to the consumers based on the output of the result query. Suppose the alert query will give me the below output table after one run:

alt text

Now, based on the consumer names, I should be getting email alerts to different **email Ids** with different email subjects dynamically. So that I don't need to set up multiple alert stanzas in savedsearches.conf for different email recipients.

Please let me know how I can implement this.

0 Karma

chandrasekharko
Path Finder

Install and use sendresults app from the splunkbase to do so.

0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma

cmerriman
Super Champion

have you seen this answer?

https://answers.splunk.com/answers/213340/how-to-get-splunk-sendemail-command-to-send-multip.html

I think this might be an approach that will work for your ask.

This documentation might also help. If there is a way you can join email addresses to the consumer, you could use $result.email$ in the To field of the alert.
http://docs.splunk.com/Documentation/Splunk/7.2.0/Alert/Emailnotification#Example_-_Send_email_to_di...

0 Karma

isamrat
Explorer

Thanks for your insights. But I would rather prefer to have some solution based on scripting. Let me know if you have any solution based on scripting.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...