Alerting

how to add add text from file - splunk alerts

marellasunil
Communicator

I wanted to add a text (What action need to be taken) for each splunk alerts, Can somebody help me to do?

Tags (2)
0 Karma

meenal901
Communicator

For conditional action, you will need to put it in a lookup file (based on exception/alarm message)
and add it to search results.
Use table and transpose to display all the data in a user-friendly format.
e.g:

Time of Exception: 2015/11/08 15:55:09
Alarm severity: High
Exception message: Unable to connect to server
Stack Trace: ---
POC: ProductionsupporDL
Action: Contact , Raise a ticket at OR Restart the server

woodcock
Esteemed Legend

Go to Settings -> Server settings -> Email settings and modify the Email footer text. This is included in all emails that your Search Head will send.

0 Karma

DavidHourani
Super Champion

This will be included in all emails right ? It won't be a conditional footer, would it ?

0 Karma

woodcock
Esteemed Legend

Correct, it is a .sig for all emails.

richgalloway
SplunkTrust
SplunkTrust

The lookup command may be helpful, but it's hard to know without more detail about what you are trying to accomplish.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...