Knowledge Management

Include details and summary in alerts?

srowe
Explorer

Hi fellow splunkers 🙂

I am a splunk newbie so forgive me if this question is pretty basic. I have an alert set up with splunk that is working great. Basically it is set up to run every half hour if the number of events returned in the search is > 20. Currently the alert sends out an email with the event details in the body of the email. This is fine if the number of events is, say around 30 or so. However, if we say over 100 events, it becomes more difficult for the email recipient to navigate through the results.

What I'd like to do is have two searches really. One with a summary of counts of events rolled up by a certain dimension (in this case IP address). So, in the body of the email we'd see something like the following:

IP Address Event_Count
999.999.999.1 20
999.999.999.2 45
....

and so on. However, our email recipients of this alert also need to know the details. Here is where I'd like to be able to also attach a .csv file with the results of a detailed search which would include timestamp, ip address, host, ...etc. Is this possible?

Thanks! Sarah

Tags (1)
0 Karma

Michael_Schyma1
Contributor

You cannot send it as both inline and CSV, from the same search. Splunk does not currently support this, but they said it is possible that in the future it will be. If you want to create a duplicate search to do the same thing and send one as CSV and one as Inline, then that will work. The problem with that is two emails will be received instead of having them blended into one.
I hope i answered the question i am not really sure if that is what you are looking for.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...