I am new to Splunk after investigating from last 7 days not able to conclude on way of implementation.
Wanted to create an app which will execute a search at specific time, then search result will be processed by a python script existing in app only.
Is it possible ?
Any basic information will help to understand and build the app.
Please suggest.
Regards,
Amit Vikram
Create a saved search with the criteria and define a action.script.command for this search, this will call your python script. See http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Configuringscriptedalerts