Hi @woodcock. This is very helpful, and somewhat of a game changer in sending dynamic alerts from Splunk. Thank you! I did have a quick question about outputcsv. From what I've read, outputlookup writes to a lookup file that replicates across a search head cluster, while outputcsv just writes a CSV in the current search head's var/run directory. I'm looking to have this result dataset NOT be persistent. Do you have any recommendations about creating a result dataset for the map command that will age out after the search is run, or some configurable time after?
... View more