@PickleRick Thanks for your prompt response.... We have Oracle OEM sending out error messages via emails to some users and we need a splunk specific account which can be added on this mail. So we would need to ingest actual mail body as they contain info about Oracle alerts. These users have domain/NT account email IDs (O365). Need help regarding what app to use compatible with splunk 8.0.0 and some details of how to set it up. xxxxxxxxxxxxxxxxxxxSAMPLE MAILxxxxxxxxxxxxxxxxxxxxxxxxxxxxx From: 13 C Oracle EM Notifications Sent: Tuesday, September 28, 2021 10:22 AM To:
[email protected] Subject: EM Event: Critical:bwprod - SQL running For Long TIme: UserInfo = Inst: 3\,SID:2338 \, OSUSER:xxxxxx-yyyy \, machine:US*******\, sql_id:2ptaaaaaaaaaaaaar Time(in mins) = 76 Host=us********** Target type=Cluster Database Target name=bwprod2 Categories=Performance Message=SQL running For Long TIme: UserInfo = Inst: 3\,SID:2338 \, OSUSER:xxxxxx-yyyy \, machine:US*******\, sql_id:2ptaaaaaaaaaaaaar Time(in mins) = 76 Severity=Critical Event reported time=Sep 28, 2021 10:22:13 AM EDT Operating System=Linux Platform=x86_64 Associated Incident Id=3777777 Associated Incident Status=New Associated Incident Owner= Associated Incident Acknowledged By Owner=No Associated Incident Priority=None Associated Incident Escalation Level=0 Event Type=Metric Alert Event name=ME$Long_running_queries:Elapsed_Time_mins Metric Group=ME$Long_running_queries Metric=Elapsed_Time_mins Metric value=76 Key Value=Inst: 3\,SID:2338 \, OSUSER:xxxxxx-yyyy \, machine:US*******\, sql_id:2ptaaaaaaaaaaaaar Time(in mins) = 76 Key Column 1=Userinfo Rule Name=xxxxxxxxxxxxxxx Rule Owner=xyxyxyxyx Update Details: SQL running For Long TIme: UserInfo = Inst: 3\,SID:2338 \, OSUSER:xxxxxx-yyyy \, machine:US*******\, sql_id:2ptaaaaaaaaaaaaar Time(in mins) = 76 Incident created by rule (Name = Incident management rule set for all targets, Create incident for critical metric alerts [System generated rule]). Thanks, Neerav
... View more