Reporting

combining alerts into one daily email report

vincenp2
New Member

I want to generate one daily email showing ALL DMC alerts that have been produced in the last 12 or 24 hours, and wondered if it is possible?

alerts are generated individually for each of the 8 main DMC alerts, and we currently receive individual emails for these.
I would like to be presented with one email at the start of the day showing me alerts which have been reported out in the last 12 or 24hrs

thanks

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

View solution in original post

0 Karma

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...