Alerting

Use splunk commands in splunk alert shell script

sharafat1187
New Member

Hello,

I am working on writing a shell script which will get executed after an splunk alert.
after processing the alert results in the shell script, i want to use splunk's "sendemail" command in the shell script.
Can somebody tell me is it possible to use splunk commands in the shell script?
if not how can i send email from that shell script?
I do not have any control on the splunk server as it is owned by devops team.

0 Karma

valiquet
Contributor

Why don't you process the results within SPlunk with a scheduled alert? You should be able to send an email.

Also with ./bin/splunk you can run a search with |sendmail cmd

Otherwise, I would setup a savedsearch that send an email every time it runs, then run it from shell. Otherwise, use OS deamon

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...