Alerting

Use splunk commands in splunk alert shell script

sharafat1187
New Member

Hello,

I am working on writing a shell script which will get executed after an splunk alert.
after processing the alert results in the shell script, i want to use splunk's "sendemail" command in the shell script.
Can somebody tell me is it possible to use splunk commands in the shell script?
if not how can i send email from that shell script?
I do not have any control on the splunk server as it is owned by devops team.

0 Karma

valiquet
Contributor

Why don't you process the results within SPlunk with a scheduled alert? You should be able to send an email.

Also with ./bin/splunk you can run a search with |sendmail cmd

Otherwise, I would setup a savedsearch that send an email every time it runs, then run it from shell. Otherwise, use OS deamon

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...