How to run a shell script alert action in splunk web and how to pass parameters to the script

New Member


I have an alert which triggers host name and task name. whenever an application status is down on any of the servers. I would like to run a script alert action based on triggered alert where the script will reset the status of application to UP. In doing so, I had to pass hostname and Taskname as parameters to the script.How can I pass those particular arguments to the script and please do let me know how to make this alert action by using splunk web? A detailed explanation would be appreciated


Tags (1)
0 Karma



The run a script alert action is officially deprecated but it still works in most of the recent versions.

This should help you to start with :

Ideally you have to process the gzip file and get your data.

Alternatively as suggested by splunk, you could use

0 Karma