Alerting

take SID in an alert

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I need to use SID as filename in an outputcsv command.
I reached to do this in a normal search

my_search
| ...
| addinfo
| outputcsv [ search * | head 1 | addinfo | eval query="my_alert_".info_sid | fields query | format "" "" "" "" "" "" ] singlefile=1

and I have a file called "my_search_1234567890.12345.csv".

The problem is when I schedule this search in an alert because the output csv is "my_search_schedule_admin.csv", in other words: running an alerts, instead SID I have the fixed string "schedule_admin".

Anyone has an idea where to search solution or (best) has a solution to solve the problem?

Thank you in advance.

Bye.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Just FYI, if you are using search head pooling or search head clustering then outputcsv is not compatible, see reference doc http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Outputcsv#Distributed_deployments

0 Karma

gcusello
SplunkTrust
SplunkTrust

None of them: it's a single Search Head!
Anyway, my search correctly runs in search mode, there's this strange behavior only running as alert.
Thanks.
Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

One additional information: I found that this problem there's only on a Windows machine, on a Linux machine I have the correct SID.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...