Splunk Enterprise

How to set the script execution within the report schedule to once?

liesofpooh
New Member

I'm thinking of running a script(.BAT file) with an action in the report schedule.
However, when I specify a batch file for the script and run it, but the script is repeatedly executed the same number of times as the number of search results.
I want to set the script execution within the report schedule to once, regardless of the search results.
What settings should I make? (ex. Advanced Edit properties)

Labels (1)
Tags (1)
0 Karma

liesofpooh
New Member

Thanks for the reply! I confirmed that there is a Trigger in the Alert Settings screen.
However, this case is about setting up a Report to perform an action based on the search results. The configuration item you told me was not present in the Report Schedule Settings.

After doing some research on my own, I found that the item alert.digest_mode in savedsearches.conf may correspond to this, so I will try changing this setting.

0 Karma

_JP
Contributor

For your Alert, make sure the Trigger setting is Once in the Trigger Conditions section:

 

alert_trigger.png

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...