Reporting

Is the saved search called by the map command allowed to send emails/run scripts?

alexl1
Path Finder

hi, I want to send an email / run a script one time each for a bunch of ip's in a list, so I was going to iterate over them with the map function with a saved search, instead of setting up a separate saved search for each ip. However I can't get the emails to send. Is the saved search called by the map function allowed to send emails/run scripts?

Thanks,

0 Karma
1 Solution

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

View solution in original post

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @alexl1, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

0 Karma
Get Updates on the Splunk Community!

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...