Alerting

I created an alert where a batch file needs to be run when triggered, but why am I getting null (" ") for %8?

harish_ka
Communicator

I created an alert where a batch file needs to be run when triggered. In the batch file I used the command

echo  %0, %1, %2, %3, %4, %5, %6, %7, %8 >>

where I am getting null " " for %8 (file where the results are stored).
Pls someone help me to find the solution.

I need to get the search results as well. Let's say I have 2 columns named ColA & ColB. How do I get the search results for these 2 columns?

0 Karma

woodcock
Esteemed Legend

It is the 8th variable so it is the 7th 0-based index (e.g. %7). Also, the results are gzipped so you will have to gunzip them.

0 Karma

harish_ka
Communicator

i tried %9 and it worked, i am trying in 6.3.1 version.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...