Alerting

Splunk managed cloud services: Why am I unable to send an alert using Search Processing Language?

raomu
Explorer

Hi,

We are using Splunk managed cloud services and I am trying to send an alert using Search Processing Language. Schedule alerts work fine, but when I am trying to send an alert using SPL it never works.

Here is my query :

| eval emailDistributionTO = if (Contact = "MACK","mack@XXX.com")
| eval emailDistributionCC = "SEOUL@XXX.com"
| eval AlertName="Domain Controllers Missing "
| eval SeverityLevelMsg="[*INFO*]"
| table Domain_Controllers Status SeverityLevelMsg Location Contact AlertName emailDistributionTO emailDistributionCC
0 Karma

iandrews_splunk
Splunk Employee
Splunk Employee

i don't see anything, in your spl, that would actually trigger an e-mail to be sent. Have you tried appending the "sendemail" command (with the required options)?

also, what would your use case be? i don't see how scheduling a search, with spl that sends and alert, would be any better than simply making a normal alert

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!