Alerting

How to send a scheduled report from Splunk to another device location ?

vrmandadi
Builder

I have a report which runs every 24 hours .i want this report to be sent to another machine each time this report runs.

1)where do I need to write the script?(Search head or Indexer)
2)What is the location of the script that needs to be placed?
3)I tried using the alert actions to run a script but it says the action is deprecated
4)What are the other options for this?

Thanks in advance

0 Karma

harsmarvania57
Ultra Champion

Hi,

  1. You need to write script on Search Head (I'll suggest to use custom alert actions for this)
  2. Have a look at Custom Alert Actions documentation, you need to create dedicated add-on for this.
  3. Run a script is deprecated and will be removed in future version of splunk so move to new framework called Custom Alert Actions
  4. I am not aware of any other option because custom alert actions works very good.
0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...