Reporting

Is there a way to retrieve the messages from the banner at the top of the UI and email me a report on them?

yannK
Splunk Employee
Splunk Employee

I wanted to have a check of the messages displayed on the top of the UI and email me a report on them, instead of logging in to see them.

Tags (4)
1 Solution

yannK
Splunk Employee
Splunk Employee

And I found this search to get them :

| rest /services/messages | table title message severity timeCreated_iso published splunk_server author 

Then schedule it with an alert to email me a copy once a while.


PS : If you want to create messages for your users on the fly from the command line

curl -k -u admin:changeme https://localhost:8089/services/messages -d severity="warn" -d name=message -d value="This is your Splunk Admin, there will be a maintenance of this instance in 10 minutes -> 15:00 , ETA of 30 minutes -> 15:30, for updates contact me at YourFriendlyNeighborhoodAdmin@mydomain.com"

View solution in original post

yannK
Splunk Employee
Splunk Employee

And I found this search to get them :

| rest /services/messages | table title message severity timeCreated_iso published splunk_server author 

Then schedule it with an alert to email me a copy once a while.


PS : If you want to create messages for your users on the fly from the command line

curl -k -u admin:changeme https://localhost:8089/services/messages -d severity="warn" -d name=message -d value="This is your Splunk Admin, there will be a maintenance of this instance in 10 minutes -> 15:00 , ETA of 30 minutes -> 15:30, for updates contact me at YourFriendlyNeighborhoodAdmin@mydomain.com"

martin_mueller
SplunkTrust
SplunkTrust

For completeness' sake, you can also add messages through the UI by going to Settings -> User Interface -> Bulletin Messages.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...