Reporting

Is the saved search called by the map command allowed to send emails/run scripts?

alexl1
Path Finder

hi, I want to send an email / run a script one time each for a bunch of ip's in a list, so I was going to iterate over them with the map function with a saved search, instead of setting up a separate saved search for each ip. However I can't get the emails to send. Is the saved search called by the map function allowed to send emails/run scripts?

Thanks,

0 Karma
1 Solution

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

View solution in original post

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @alexl1, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma

justinatpnnl
Communicator

You should be able to do this without using the map command. You just need to have the email address in your search results.

example:

alt text

Then you can set up an alert action to send an email FOR EACH RESULT using the value from the email field in the TO address:

alt text

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...