I was trying to create a cron-scheduled alert in Splunk, that would trigger a mail with the notable event, urgency and trigger time.
I tried it by using |es_notable_events, but it returns a large amount of data.
Is there any other solution?
Try below suggestions:
Can you accept the answer if it's helped you? Thanks.