Reporting

combining alerts into one daily email report

vincenp2
New Member

I want to generate one daily email showing ALL DMC alerts that have been produced in the last 12 or 24 hours, and wondered if it is possible?

alerts are generated individually for each of the 8 main DMC alerts, and we currently receive individual emails for these.
I would like to be presented with one email at the start of the day showing me alerts which have been reported out in the last 12 or 24hrs

thanks

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

View solution in original post

0 Karma

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...