Getting Data In

Is it possible to have Splunk kick off a script each time it receives a log from a particular log source?

treydismukes
Engager

I have some security devices that are sending logs to my Splunk server. I'd like to have a script on the Splunk server that kicks off each time it receives an alert from my device.

Details:
Security device is sending alerts to my Splunk server.
The script will examine each alert as it comes in.
Based on the contents of the alert it will either ignore it (low priority alert) or forward it to a regional contact for remediation (high priority alert)

Tags (2)
0 Karma

lukejadamec
Super Champion

Yes. This is a very standard use case for Splunk.
Create a search that runs real-time or at an interval that will pull the high priority alerts, save the search as an alert, and set the alert action to Run A Script.

linu1988
Champion

Keep in mind the scripts will be running every instance on the search if realtime not only when the search matches the result. So proper logic should be present to avoid null emails to the destination.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...