Alerting

Use splunk commands in splunk alert shell script

sharafat1187
New Member

Hello,

I am working on writing a shell script which will get executed after an splunk alert.
after processing the alert results in the shell script, i want to use splunk's "sendemail" command in the shell script.
Can somebody tell me is it possible to use splunk commands in the shell script?
if not how can i send email from that shell script?
I do not have any control on the splunk server as it is owned by devops team.

0 Karma

valiquet
Contributor

Why don't you process the results within SPlunk with a scheduled alert? You should be able to send an email.

Also with ./bin/splunk you can run a search with |sendmail cmd

Otherwise, I would setup a savedsearch that send an email every time it runs, then run it from shell. Otherwise, use OS deamon

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...