Splunk Search

Setting a default action for alert in splunk

kteng2024
Path Finder

HI,

Is there anyway in splunk to set the "email" as default trigger action for an alert.

0 Karma

somesoni2
Revered Legend

You can use [default] stanza in savedsearches.conf to assign an attribute to all saved searches. You can use attributes described in below link to setup your email alert.

http://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Savedsearchesconf#Settings_for_email_action

Please note that this will get applied to all scheduled searches (unless overridden at search level).

0 Karma

kteng2024
Path Finder

Can i set the webhook as default trigger action as in the documentation i see only for email.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...