Hi,
We are using Splunk managed cloud services and I am trying to send an alert using Search Processing Language. Schedule alerts work fine, but when I am trying to send an alert using SPL it never works.
Here is my query :
| eval emailDistributionTO = if (Contact = "MACK","mack@XXX.com")
| eval emailDistributionCC = "SEOUL@XXX.com"
| eval AlertName="Domain Controllers Missing "
| eval SeverityLevelMsg="[*INFO*]"
| table Domain_Controllers Status SeverityLevelMsg Location Contact AlertName emailDistributionTO emailDistributionCC
i don't see anything, in your spl, that would actually trigger an e-mail to be sent. Have you tried appending the "sendemail" command (with the required options)?
also, what would your use case be? i don't see how scheduling a search, with spl that sends and alert, would be any better than simply making a normal alert