Reporting

6.1 - Ability to use field value as email destination for scheduled search

hortonew
Builder

Is there any ability built in to splunk to use a field from a returned search, as a dynamic field in a scheduled search? I'm trying to use a "to" field as the destination (to) field in a schedule email alert.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

martin_mueller
SplunkTrust
SplunkTrust

No need for any App - just use $result.field$ in your to-field.

6.1-specific docs: http://docs.splunk.com/Documentation/Splunk/6.1/Alert/Setupalertactions#Use_tokens_in_email_notifica...

hortonew
Builder

Huh, nice. I'll try that out tomorrow as well. Thanks!

0 Karma

acharlieh
Influencer

The sendresults app/command should help you out here. It looks for a field named email_to but a rename can work wonders: https://splunkbase.splunk.com/app/1794/

hortonew
Builder

Thanks - didn't think to look at prebuilt apps. I'll dive in and see what it's all about. Appreciate it.

0 Karma

hortonew
Builder

Works like a charm - definitely the way to go. Thanks again.

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...