Building for the Splunk Platform

how can i retrieve the search URL and name of a scheduled search using Intersplunk?

awurster
Contributor

Previously, I was using CSV reader and alert scripts to process a saved search and export to a 3rd party tool (JIRA). The splunk "title" or "name" gets turned into an "issue summary".

My previous code looked like:

search_summary = sys.argv[4]
search_url = sys.argv[6]

Now, I'm trying to modify this into a search command using Intersplunk:

search_results, dummy_results, search_settings = splunk.Intersplunk.getOrganizedResults()

How can i retrieve the search's "name" and/or a URL pointing back to it?

dolivasoh
Contributor

These are all passed as arguments to a script when alerting. Try setting your saved search to alert and capture the arguments.

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...