Other Usage

How to send user login fail alerts to specific users (who have 4625)?

10061987
Engager

Hi there,

I want to send email who have 4625 over 20 login fail count. I have search there is no problem about search but i couldn't figure out to send emails to specific users who have 4625 login fail events. I know trigger action like send mail but i couldn't figure out how to send specific users. I don't want to send email to a group, i need send email to specific users who have 4625 events.

 

Any help would be appreciated!

Labels (1)
0 Karma

meetmshah
Contributor

Hello @10061987,

You can use fields from the first line of the results in the alert, e.g. $result.email$ assuming your search includes the email field. Then if you trigger the alert for each result (rather than just once), each result will execute the action with its corresponding row from the events.

Reference - https://community.splunk.com/t5/Alerting/Splunk-Alerts-How-to-use-email-address-from-variable/m-p/63....

 

Please accept the solution and hit Karma, if this helps!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

There is also an app providing a more flexible email command than the builtin sendemail one. Don't remember the name but ir's easily findable on Splunkbase.

Having said that, remember that it's risky to use "external" data this way because you might end up sending emails (and a lot of them sometimes) to non-existent, or empty email addresses.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...