I have a requirement to trigger an alert email per Service in case of failures.
I don't want to create separate alerts for each service.
My search returns below results example -
ServiceName Status Time EmailContact ABC failed 1/13/2017 8.50 am email@example.com ABC failed 1/13/2017 8.55 am firstname.lastname@example.org DEF failed 1/13/2017 9.00 am email@example.com
How to get two emails from Splunk for ServiceName-ABC and ServiceName DEF?
First email should sent to firstname.lastname@example.org with below 2 rows
ServiceName Status Time EmailContact ABC failed 1/13/2017 8.50 am email@example.com ABC failed 1/13/2017 8.55 am firstname.lastname@example.org
Second email should sent to email@example.com with below 1 rows
ServiceName Status Time EmailContact DEF failed 1/13/2017 9.00 am firstname.lastname@example.org
I have tried to use "map" command in the Custom trigger condition but it is not working.
Please tell me the approach to accomplish this. Thanks !!
Your Base Search Here | outputlookup MyTempLookup.csv | stats count by EmailContact | map maxsearches=9999 search="|inputlookup MyTempLookup.csv | search EmailContact=$EmailContact$ | sendemail to=\"$EmailContact$\" format=raw subject=myresults sendresults=true"