Alerting

How to send a scheduled report from Splunk to another device location ?

vrmandadi
Builder

I have a report which runs every 24 hours .i want this report to be sent to another machine each time this report runs.

1)where do I need to write the script?(Search head or Indexer)
2)What is the location of the script that needs to be placed?
3)I tried using the alert actions to run a script but it says the action is deprecated
4)What are the other options for this?

Thanks in advance

0 Karma

harsmarvania57
Ultra Champion

Hi,

  1. You need to write script on Search Head (I'll suggest to use custom alert actions for this)
  2. Have a look at Custom Alert Actions documentation, you need to create dedicated add-on for this.
  3. Run a script is deprecated and will be removed in future version of splunk so move to new framework called Custom Alert Actions
  4. I am not aware of any other option because custom alert actions works very good.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...