Alerting

How do you search Splunk for a listing of all alerts that are being sent to a particular email address?

ChadLangUAB
Path Finder

Does anyone know how to Splunk a listing of all alerts that are sending to a particular email address (e.g. ServiceNow) or get a listing of all alerts by email address they’re being delivered to?

I'm working to analyze our processes and the mechanisms currently being used.

0 Karma
1 Solution

zonistj
Path Finder

You can use the rest function to search for this information:

| rest splunk_server=local count=0 /services/saved/searches
| search eai:acl.app="*" title="*" action.email.to="*"
| table eai:acl.app,title,action.email.to, next_scheduled_time, search

Just replace any of the asterisks to search for specific apps, saved search names, or the email recipient. You can add "action.email.cc" to include any CC addresses.

View solution in original post

0 Karma

zonistj
Path Finder

You can use the rest function to search for this information:

| rest splunk_server=local count=0 /services/saved/searches
| search eai:acl.app="*" title="*" action.email.to="*"
| table eai:acl.app,title,action.email.to, next_scheduled_time, search

Just replace any of the asterisks to search for specific apps, saved search names, or the email recipient. You can add "action.email.cc" to include any CC addresses.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...