Alerting

Is there a action available in Spluk alert to store in index ?

nandha_2
Engager

Hi,
I would like to move saved search aka Alert to an index instead of triggering an email ? is it possible in splunk to do that ?

Thanks
nandha

Tags (1)
0 Karma

lguinn2
Legend

You cannot place an alert directly into an index. However, you could trigger a script as an alert action. The script could write data to a log file (maybe you could call it "alert.log"). Have Splunk monitor the log file (alert.log) and index it.
Voila! You now have information about your alerts in an index.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!