Splunk Enterprise

How to set the script execution within the report schedule to once?

liesofpooh
New Member

I'm thinking of running a script(.BAT file) with an action in the report schedule.
However, when I specify a batch file for the script and run it, but the script is repeatedly executed the same number of times as the number of search results.
I want to set the script execution within the report schedule to once, regardless of the search results.
What settings should I make? (ex. Advanced Edit properties)

Labels (1)
Tags (1)
0 Karma

liesofpooh
New Member

Thanks for the reply! I confirmed that there is a Trigger in the Alert Settings screen.
However, this case is about setting up a Report to perform an action based on the search results. The configuration item you told me was not present in the Report Schedule Settings.

After doing some research on my own, I found that the item alert.digest_mode in savedsearches.conf may correspond to this, so I will try changing this setting.

0 Karma

_JP
Contributor

For your Alert, make sure the Trigger setting is Once in the Trigger Conditions section:

 

alert_trigger.png

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...