Splunk Enterprise

How to send email alert where email is taken from the logs ?

haripriyasarve1
Explorer

Hi Everyone,

I have data like below,

Certificate1, expirydate-15/7/2020, a@gmail.com

Certificate2, expirydate-18/7/2020, b@gmail.com

I need to setup email alerts in such a way, when expiry date is today , need to send alert to that particular email id automatically. 

I have around 1000 certificates, so if I do it manually, it takes so much time. Is there a way where we can automate this? Please help out.

 

Labels (1)
Tags (2)
0 Karma

rnowitzki
Builder

Hi @haripriyasarve1,

You could create a field that includes the email from the search results and in the Alert settings add a token to reference that field in the "To" box like $result.fieldname$

https://docs.splunk.com/Documentation/Splunk/8.0.5/Alert/EmailNotificationTokens

Hope that helps

Ralph

 

 

--
Karma and/or Solution tagging appreciated.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...