Alerting

Programmatically generate an alert

leustean
Explorer

Hello,

As the title states I would like to know if it is possible to generate programmatically an alert and then inject it into Splunk. Then Splunk would act based on this alert by sending an email, or writing to the syslog etc.

Personally I would image this is something that can be obtained using the Splunk Rest API

I would be interested for any direction towards obtaining this goal.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can programmatically insert an event into Splunk. You can then set up a real-time search for that event and trigger an alert when it is found.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...