Alerting

How to configure the same alert for internal and external client

amitlookin
Loves-to-Learn Lots

i have a alert created in Splunk. Can anyone please guide as to what setting has to be done in Edit Alert->Trigger Alert-> Send Email section to make sure that when the alert triggers and if the email has to be sent internally then it should have subject line as [INTERNAL]{Subject line content} with defined recipient and if the email has to be sent outside the organisation the subject line should be {Subject line content} with its defined recipient list.

Do i need to create 2 separate copies of same alert with these 2 configuration in Edit Alert setting defined or these both conditions can be saved in the configuration for single alert.

 

 

Labels (2)
0 Karma

cmerriman
Super Champion

Do different lines of the alert get sent to different recipients? Or is it just that one copy of the alert get sent internally and one copy of the exact same dataset get sent externally?

0 Karma

amitlookin
Loves-to-Learn Lots

The alert is same with same logic the only difference lies in the subject line and the message body depending upon to whom the alert will be send (Internal or External to the organisation).

Thanks for responding.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...