Splunk Search

Setting a default action for alert in splunk

kteng2024
Path Finder

HI,

Is there anyway in splunk to set the "email" as default trigger action for an alert.

0 Karma

somesoni2
Revered Legend

You can use [default] stanza in savedsearches.conf to assign an attribute to all saved searches. You can use attributes described in below link to setup your email alert.

http://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Savedsearchesconf#Settings_for_email_action

Please note that this will get applied to all scheduled searches (unless overridden at search level).

0 Karma

kteng2024
Path Finder

Can i set the webhook as default trigger action as in the documentation i see only for email.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...