@LCelley As noted, you'll need to deploy a service exposed to Splunk Cloud email or webhook output. There are countless ways to do this, but the main problem is security. Your options for authenticating and authorizing commands sent from Splunk Cloud are very limited. An on-premise search head ("hybrid search") is probably a much safer option. I'm not sure why Splunk limits the ScheduledSearch feature in this license context, though. You'll want to contact your sales team (not support) and discuss your use case.
... View more