Splunk Enterprise

To get details for all email alerts sent with results.

agoyal
Builder

Hi,

I am looking to build a dashboard where I can track all the email sent on configured alerts. 

I have used  Alert manager App where I can get these details except couple of details. 

I am also looking  to get the details of recepient list and subject(optional),  which I guess not avaiable. 

agoyal_0-1591881506324.png



I am aware of internal logs (sourcetype=splunk_python) where we get details of all email sent by splunk. but I couldn't find a way to map those details with details in alert manager.

splunk_python log
2020-06-10 17:15:14,882 +0200 INFO sendemail:139 - Sending email. subject="[PS_PI45_KERNEL_ELEMENTS] Splunk CPU Alert", results_link="http://splunk:8000/apps/xxxxx/@go?sid=scheduler__admin__xxxxx__RMD56802a2f6671046cd_at_1591802100_15918", recipients="[u'xyz@xxxxx.com', u'abc@xxxxx.com']", server="smtp.murex.com"

Alert Manager

agoyal_1-1591881781241.png

 

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...