Splunk Enterprise

How to set the script execution within the report schedule to once?

liesofpooh
New Member

I'm thinking of running a script(.BAT file) with an action in the report schedule.
However, when I specify a batch file for the script and run it, but the script is repeatedly executed the same number of times as the number of search results.
I want to set the script execution within the report schedule to once, regardless of the search results.
What settings should I make? (ex. Advanced Edit properties)

Labels (1)
Tags (1)
0 Karma

liesofpooh
New Member

Thanks for the reply! I confirmed that there is a Trigger in the Alert Settings screen.
However, this case is about setting up a Report to perform an action based on the search results. The configuration item you told me was not present in the Report Schedule Settings.

After doing some research on my own, I found that the item alert.digest_mode in savedsearches.conf may correspond to this, so I will try changing this setting.

0 Karma

_JP
Contributor

For your Alert, make sure the Trigger setting is Once in the Trigger Conditions section:

 

alert_trigger.png

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...