Alerting

Why do I not get any output from Argument 6 from a splunk alert script?

tshay
Engager

In Splunk 6.2.2, I am trying to run a script to output a link to the saved search using argument 6 found here: http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing...

Arguments 1-5 and 8 are working correctly, however argument 6 does not return anything. This is the batch file I am using:
@echo off
echo %SPLUNK_ARG_6% > "C:\Users[username]\Documents\Splunk\test_output.txt"

0 Karma
1 Solution

Yasaswy
Contributor

Hi.. just curious on what you are seeing for %SPLUNK_ARG_8%. Typically the same could be expected for 6 as well... might lend a clue.
eg:

Assuming this is from an app... path can be relative

6) http://yoursplunk:8000/app/appname/@go?sid=abcdef
vs 
8)/PathTo_splunk/var/run/splunk/dispatch/abcdef/results.csv.gz

View solution in original post

Yasaswy
Contributor

Hi.. just curious on what you are seeing for %SPLUNK_ARG_8%. Typically the same could be expected for 6 as well... might lend a clue.
eg:

Assuming this is from an app... path can be relative

6) http://yoursplunk:8000/app/appname/@go?sid=abcdef
vs 
8)/PathTo_splunk/var/run/splunk/dispatch/abcdef/results.csv.gz

tshay
Engager

Hi,

This is what I am getting for %SPLUNK_ARG_8%:C:/ProgramFiles/Splunk/var/run/splunk/dispatch/rt_scheduler_adminsearch_errorcode20_at_1431029291_8.55/per_result_alert/tmp_8.csv.gz

When I go to
//localhost:8000/app/search/@go?sid=rt_scheduler_adminsearch_errorcode20_at_1431029291_8.55

The link brings up the search! Thanks for your help. Arg 6 is still not working for me through a script, but I can just scrape the info from arg 8.

Thanks again

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...