Splunk Enterprise

How to set the script execution within the report schedule to once?

liesofpooh
New Member

I'm thinking of running a script(.BAT file) with an action in the report schedule.
However, when I specify a batch file for the script and run it, but the script is repeatedly executed the same number of times as the number of search results.
I want to set the script execution within the report schedule to once, regardless of the search results.
What settings should I make? (ex. Advanced Edit properties)

Labels (1)
Tags (1)
0 Karma

liesofpooh
New Member

Thanks for the reply! I confirmed that there is a Trigger in the Alert Settings screen.
However, this case is about setting up a Report to perform an action based on the search results. The configuration item you told me was not present in the Report Schedule Settings.

After doing some research on my own, I found that the item alert.digest_mode in savedsearches.conf may correspond to this, so I will try changing this setting.

0 Karma

_JP
Contributor

For your Alert, make sure the Trigger setting is Once in the Trigger Conditions section:

 

alert_trigger.png

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...