Alerting

How to get Single Email for all the alerts created

pkumar2
Explorer

I have 6 alerts and each send 6 mails when triggered, This clutters the inbox of receivers of the alerts.

Is there a way to have one single mail, with all alerts data listed in it.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The six different alerts cannot be combined, but you can tell each to send a single email with all results rather than an email message for each result. That will cut down the messages from 36 to 6.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gjanders
SplunkTrust
SplunkTrust

Along these lines perhaps you could create a single alert and use sendresults (splunkbase) to (more) programmatically send emails?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...