Deployment Architecture

How to run a script from an app as an alert action in a search head cluster?

davebo1896
Communicator

I'm trying to run a script from an app as an alert action.
The script is in $SPLUNK_HOME/etc/apps/foo/bin/scripts/bar.sh
Do I have to create a link $SPLUNK_HOME/bin/scripts/bar.sh to point to $SPLUNK_HOME/etc/apps/foo/bin/scripts/bar.sh
or should $SPLUNK_HOME/etc/apps/foo/bin/scripts/bar.sh already be in the PATH?

0 Karma
1 Solution

somesoni2
Revered Legend

The path for the scripts that can be used in alert action for search should be $APP_HOME/bin/ (not $APP_HOME/bin/scripts). You would not need any link.

http://docs.splunk.com/Documentation/Splunk/6.2.5/AdvancedDev/ShareYourWork#Files_and_directories_fo...

View solution in original post

somesoni2
Revered Legend

The path for the scripts that can be used in alert action for search should be $APP_HOME/bin/ (not $APP_HOME/bin/scripts). You would not need any link.

http://docs.splunk.com/Documentation/Splunk/6.2.5/AdvancedDev/ShareYourWork#Files_and_directories_fo...

davebo1896
Communicator

I'll give that a try.

What has confused me, is a readme.txt in /opt/splunk/bin/scripts
$ cat /opt/splunk/bin/scripts/readme.txt
Scripts placed in this directory can be called by Alerts for execution

0 Karma

davebo1896
Communicator

$APP_HOME/bin works !

The documentation for creating alert actions is incorrect:
The script or batch file that an alert triggers must be at either of the following locations:

$SPLUNK_HOME/bin/scripts
$SPLUNK_HOME/etc/apps//bin/scripts

Thanks for your help.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...