invoking alert action from spl query or command line


I have a parameterized query which returns results.

I have an alert action to send the results to some location as configurable item

Based on the different criterion.....I should call the alert action passing different location values.

I am currently creating manually all the different criterion wrappers and attach specific location values.

If there is a way either in spl or command line to call the alert action on top of the results returned then instead of creating wrapper savedsearches, I could easily script and pass appropriate values and invoke the splunk command to execute the spl.

In nutshell:

Calling alert action from spl or using command line on the query results.


Labels (1)
Tags (1)
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!