Splunk Dev

how can i retrieve the search URL and name of a scheduled search using Intersplunk?

awurster
Contributor

Previously, I was using CSV reader and alert scripts to process a saved search and export to a 3rd party tool (JIRA). The splunk "title" or "name" gets turned into an "issue summary".

My previous code looked like:

search_summary = sys.argv[4]
search_url = sys.argv[6]

Now, I'm trying to modify this into a search command using Intersplunk:

search_results, dummy_results, search_settings = splunk.Intersplunk.getOrganizedResults()

How can i retrieve the search's "name" and/or a URL pointing back to it?

dolivasoh
Contributor

These are all passed as arguments to a script when alerting. Try setting your saved search to alert and capture the arguments.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...