Splunk Search

How do I email customized stats tables to individual employees?

matthewg
Explorer

I want to send an alert to each Employee once a day with a stats table customized to that employee: for instance the search looks similar to:

user="username" result="hit" OR result="miss" | stats earliest(_time), count, dc(result), max(score) by referer

How can I divide this into multiple tables, one for each username that splunk finds and send each user their own table?

I know that I can use the variable $result.user$ in my alert in the To: field like $result.user$@ourdomain.com

I want to send a customized table to each user. So james@ourdomain.com would receive the results of
user="james" result="hit" OR result="miss" | stats earliest(_time), count, dc(result), max(score) by referer
but jill@ourdomain.com would receive the results of
user="jill" result="hit" OR result="miss" | stats earliest(_time), count, dc(result), max(score) by referer
etc.

Since there are several hundred users and they come and go the alert should just generate a table for each user that it finds and attempt to email the results to that user.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...