Reporting

Sending an email on new record

apaillard
New Member

Hi,

I set a search like |dbquery "dbname" select seq,msg from table order by seq desc.
Now, for each new record I would like to create an alert that sends an email.

Anthony

Tags (1)
0 Karma

apaillard
New Member

Ok my apologies, that was actually pretty simple :
I haven't seen the choice "rises by", and it did the job !!

Anthony

0 Karma

apaillard
New Member

Hi oldest,
For my understanding it will always send email as my search will everytime returns something.
I just want sending an email when the search returns one or more results as the preview search.

Anthony

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Since you have the search, you can create a scheduled search that has an alert condition, and then sends the email.

http://docs.splunk.com/Documentation/Splunk/latest/Alert/Scheduledsearch#Send_emails_to_a_set_of_sta...

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...