Hello everyone,
I'm still very new to the world of Splunk Enterprise. 😉 I hope that you can help me with my problem.
I created the following search to be notified of app updates by email:
| rest /services/apps/local | search update.version != "" | rename title AS Update_APP, version AS Update_Version, update.version AS Update_Versionupdate | table Update_APP Update_Version Update_Versionupdate
The notification type is scheduled to run every day at 12:00 p.m. I chose one as a trigger. However, I get the same ban notification email every day, even though I've already received it.
What do I have to do so that the message is only sent once.
Please excuse my bad English.
Best regards Björn
... View more