Alerting
Highlighted

Splunk alert result(s) to a dashboard input and then email results

Explorer

How can I send alert result(s) to a dashboard input and then email dashboard results? Please let me know if anybody has worked on this before. thank you!

0 Karma
Highlighted

Re: Splunk alert result(s) to a dashboard input and then email results

Explorer

If you are using the monitoring console or have it as a search peer, try the below:
index=audit action="alertfired" AND host=YOURDMC
| eval severity=case(severity==1,"debug", severity==2, "info", severity==3,"warning", severity==4,"error",severity=5,"severe",severity==6,"fatal")
| rename ss
app as monitoringapp
| table ss
name, severity, timestamp, monitoring_app

You can then create a dashbaord from this as well as an email action that has the table above inline.

0 Karma
Highlighted

Re: Splunk alert result(s) to a dashboard input and then email results

Explorer

As mentioned you can also schedule from a Dashboard itself if this fits your use case.
After a Dashboard has been created Edit > Schedule > Email To

0 Karma