How to send a scheduled report from Splunk to another device location ?


I have a report which runs every 24 hours .i want this report to be sent to another machine each time this report runs.

1)where do I need to write the script?(Search head or Indexer)
2)What is the location of the script that needs to be placed?
3)I tried using the alert actions to run a script but it says the action is deprecated
4)What are the other options for this?

Thanks in advance

0 Karma

Ultra Champion


  1. You need to write script on Search Head (I'll suggest to use custom alert actions for this)
  2. Have a look at Custom Alert Actions documentation, you need to create dedicated add-on for this.
  3. Run a script is deprecated and will be removed in future version of splunk so move to new framework called Custom Alert Actions
  4. I am not aware of any other option because custom alert actions works very good.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...