Reporting

Is it possible to send email based on certain condition?

syx093
Communicator

I am trying to send emails based on certain conditions. For example if the host=<host1> the send the email to person1@example.com. If host=<host2> send the email to person2@example.com. If have trying to use the sendemail command but I have not been successful in this attempt.

0 Karma

jeffland
SplunkTrust
SplunkTrust

An alert seems to be exactly what you want to do.
You define a search for host=host1, schedule it to run every five minutes or so, and if it returns results, you send an email to some user. You do that for all alerts you want to receive.

0 Karma

syx093
Communicator

There are about 40 different unique host and mount combination. If I understand what you are suggesting, that would me I would have to create 10 different alerts to get this working.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Oh. Well it is probably possible to do that in an automated fashion as well, maybe via a lookup to determine the adressee and with sendemail. Unfortunately, I don't know how to right off the bat.

0 Karma

syx093
Communicator

That my original approach however the field does not take other fields as an accepted argument. For example, if on of the field is called email, using to=email will make an attempt to send an email to email.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...