Alerting

how to add add text from file - splunk alerts

marellasunil
Communicator

I wanted to add a text (What action need to be taken) for each splunk alerts, Can somebody help me to do?

Tags (2)
0 Karma

meenal901
Communicator

For conditional action, you will need to put it in a lookup file (based on exception/alarm message)
and add it to search results.
Use table and transpose to display all the data in a user-friendly format.
e.g:

Time of Exception: 2015/11/08 15:55:09
Alarm severity: High
Exception message: Unable to connect to server
Stack Trace: ---
POC: ProductionsupporDL
Action: Contact , Raise a ticket at OR Restart the server

woodcock
Esteemed Legend

Go to Settings -> Server settings -> Email settings and modify the Email footer text. This is included in all emails that your Search Head will send.

0 Karma

DavidHourani
Super Champion

This will be included in all emails right ? It won't be a conditional footer, would it ?

0 Karma

woodcock
Esteemed Legend

Correct, it is a .sig for all emails.

richgalloway
SplunkTrust
SplunkTrust

The lookup command may be helpful, but it's hard to know without more detail about what you are trying to accomplish.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...