just starting test out and try splunk we need an alerting tool for linux to start
the app show built alerts but how do I create a group of admins and setup a call rotation and set that up in the built in alert for splunk
Somebody might very well have created an app to do thins kind of thing; spend some time searching splunkbase (apps.splunk.com).
well I was just gong to right a bash script but thought there must be a better way
You do this by writing a python script and then calling that script (enable "run a script" under "alert actions") when your alert is raised.