Reporting

combining alerts into one daily email report

vincenp2
New Member

I want to generate one daily email showing ALL DMC alerts that have been produced in the last 12 or 24 hours, and wondered if it is possible?

alerts are generated individually for each of the 8 main DMC alerts, and we currently receive individual emails for these.
I would like to be presented with one email at the start of the day showing me alerts which have been reported out in the last 12 or 24hrs

thanks

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

View solution in original post

0 Karma

DavidHourani
Super Champion

Hi @vincenp2,

Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like index=_internal sourcetype=scheduler should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.

Let me know if that helps.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...