Splunk Search

Is there a way to send an alert email whenever a lookup is updated?

Priya312
Explorer

Hello,

Is there is any way to send email whenever there is a change in a lookup?
I have a report which updates the lookup whenever there is a breach in threshold. I wanted to send an email whenever that lookup gets updated. Is there any way to do that?

0 Karma
1 Solution

woodcock
Esteemed Legend

You can schedule a search that uses inputlookup to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup to contain the updated original's data. This can all be done in a single search using sendemail.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You can schedule a search that uses inputlookup to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup to contain the updated original's data. This can all be done in a single search using sendemail.

0 Karma

Priya312
Explorer

Thanks woodcock. It worked..

0 Karma

woodcock
Esteemed Legend

For benefit of everyone, please share the details of your solution. I am curious whether you got it in 1 combined search or 2.

0 Karma

renjith_nair
Legend

You can watch the file and alert whenever it changes. But why don't you do at the source itself. ie: since you are running a report/scheduled search to update the lookup, include this email alert part of your report itself. For eg: If the report returns any result , create an action to send an alert. Does this work for you?

http://docs.splunk.com/Documentation/Splunk/6.4.1/Alert/Emailnotification

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...