I'm attempting to craft an alert that notifies myself and the user that requested access that they haven't revoked their access to a support site. My tool writes to splunk that they requested access, and then that they revoked access. But, if they forget to revoke access, I'd like to notify them that they forgot after 24 hours.
User johndoe (ID: 123) requested access to the site (ID: 123) located at http://subdomain.example.com.
User johndoe (ID: 123) revoked their access to the site (ID: 123) located at http://subdomain.example.com.
I'm a splunk noob, so I apologize if this is a pretty straightforward answer and I really appreciate the help.
... View more