Hi Team,
As part of an integration from Splunk ES into a ticketing system, we're trying to monitor the notable_events KV Store and create a scheduled search when the status field changes that also sends an email when it notices the status change
Has anyone else tried this or could the logic work to do this?
Appreciate this is a clunky way to do this but would be great to get some ideas
duplicate question:
duplicate question: