Reporting

Is the saved search called by the map command allowed to send emails/run scripts?

alexl1
Path Finder

hi, I want to send an email / run a script one time each for a bunch of ip's in a list, so I was going to iterate over them with the map function with a saved search, instead of setting up a separate saved search for each ip. However I can't get the emails to send. Is the saved search called by the map function allowed to send emails/run scripts?

Thanks,

0 Karma
1 Solution

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

View solution in original post

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @alexl1, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...