Alerting

how to add add text from file - splunk alerts

marellasunil
Communicator

I wanted to add a text (What action need to be taken) for each splunk alerts, Can somebody help me to do?

Tags (2)
0 Karma

meenal901
Communicator

For conditional action, you will need to put it in a lookup file (based on exception/alarm message)
and add it to search results.
Use table and transpose to display all the data in a user-friendly format.
e.g:

Time of Exception: 2015/11/08 15:55:09
Alarm severity: High
Exception message: Unable to connect to server
Stack Trace: ---
POC: ProductionsupporDL
Action: Contact , Raise a ticket at OR Restart the server

woodcock
Esteemed Legend

Go to Settings -> Server settings -> Email settings and modify the Email footer text. This is included in all emails that your Search Head will send.

0 Karma

DavidHourani
Super Champion

This will be included in all emails right ? It won't be a conditional footer, would it ?

0 Karma

woodcock
Esteemed Legend

Correct, it is a .sig for all emails.

richgalloway
SplunkTrust
SplunkTrust

The lookup command may be helpful, but it's hard to know without more detail about what you are trying to accomplish.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...