Splunk Enterprise Security

How to create a cron-scheduled alert that triggers a mail with the notable event, urgency and triggered time?

paul96
New Member

I was trying to create a cron-scheduled alert in Splunk, that would trigger a mail with the notable event, urgency and trigger time.
I tried it by using |es_notable_events, but it returns a large amount of data.

Is there any other solution?

0 Karma

jawaharas
Motivator

Try below suggestions:

  1. Increase the frequency of alert - say every 30 minutes or even lesser. So, that number events for that time period will be less.
  2. Or Configure the alert mail to send the email with 'Attach CSV' option instead of populating search results in email body.
0 Karma

jawaharas
Motivator

@paul96
Can you accept the answer if it's helped you? Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...