Deployment Architecture
Highlighted

How to run a script from an app as an alert action in a search head cluster?

Communicator

I'm trying to run a script from an app as an alert action.
The script is in $SPLUNKHOME/etc/apps/foo/bin/scripts/bar.sh
Do I have to create a link $SPLUNK
HOME/bin/scripts/bar.sh to point to $SPLUNKHOME/etc/apps/foo/bin/scripts/bar.sh
or should $SPLUNK
HOME/etc/apps/foo/bin/scripts/bar.sh already be in the PATH?

0 Karma
Highlighted

Re: How to run a script from an app as an alert action in a search head cluster?

SplunkTrust
SplunkTrust

The path for the scripts that can be used in alert action for search should be $APP_HOME/bin/ (not $APP_HOME/bin/scripts). You would not need any link.

http://docs.splunk.com/Documentation/Splunk/6.2.5/AdvancedDev/ShareYourWork#Files_and_directories_fo...

View solution in original post

Highlighted

Re: How to run a script from an app as an alert action in a search head cluster?

Communicator

I'll give that a try.

What has confused me, is a readme.txt in /opt/splunk/bin/scripts
$ cat /opt/splunk/bin/scripts/readme.txt
Scripts placed in this directory can be called by Alerts for execution

0 Karma
Highlighted

Re: How to run a script from an app as an alert action in a search head cluster?

Communicator

$APP_HOME/bin works !

The documentation for creating alert actions is incorrect:
The script or batch file that an alert triggers must be at either of the following locations:

$SPLUNKHOME/bin/scripts
$SPLUNK
HOME/etc/apps//bin/scripts

Thanks for your help.

0 Karma