Splunk Enterprise

How to set the script execution within the report schedule to once?

liesofpooh
New Member

I'm thinking of running a script(.BAT file) with an action in the report schedule.
However, when I specify a batch file for the script and run it, but the script is repeatedly executed the same number of times as the number of search results.
I want to set the script execution within the report schedule to once, regardless of the search results.
What settings should I make? (ex. Advanced Edit properties)

Labels (1)
Tags (1)
0 Karma

liesofpooh
New Member

Thanks for the reply! I confirmed that there is a Trigger in the Alert Settings screen.
However, this case is about setting up a Report to perform an action based on the search results. The configuration item you told me was not present in the Report Schedule Settings.

After doing some research on my own, I found that the item alert.digest_mode in savedsearches.conf may correspond to this, so I will try changing this setting.

0 Karma

_JP
Contributor

For your Alert, make sure the Trigger setting is Once in the Trigger Conditions section:

 

alert_trigger.png

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...