Alerting

Splunk managed cloud services: Why am I unable to send an alert using Search Processing Language?

raomu
Explorer

Hi,

We are using Splunk managed cloud services and I am trying to send an alert using Search Processing Language. Schedule alerts work fine, but when I am trying to send an alert using SPL it never works.

Here is my query :

| eval emailDistributionTO = if (Contact = "MACK","mack@XXX.com")
| eval emailDistributionCC = "SEOUL@XXX.com"
| eval AlertName="Domain Controllers Missing "
| eval SeverityLevelMsg="[*INFO*]"
| table Domain_Controllers Status SeverityLevelMsg Location Contact AlertName emailDistributionTO emailDistributionCC
0 Karma

iandrews_splunk
Splunk Employee
Splunk Employee

i don't see anything, in your spl, that would actually trigger an e-mail to be sent. Have you tried appending the "sendemail" command (with the required options)?

also, what would your use case be? i don't see how scheduling a search, with spl that sends and alert, would be any better than simply making a normal alert

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...