Splunk Search

Is there a way to send an alert email whenever a lookup is updated?

Priya312
Explorer

Hello,

Is there is any way to send email whenever there is a change in a lookup?
I have a report which updates the lookup whenever there is a breach in threshold. I wanted to send an email whenever that lookup gets updated. Is there any way to do that?

0 Karma
1 Solution

woodcock
Esteemed Legend

You can schedule a search that uses inputlookup to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup to contain the updated original's data. This can all be done in a single search using sendemail.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You can schedule a search that uses inputlookup to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup to contain the updated original's data. This can all be done in a single search using sendemail.

0 Karma

Priya312
Explorer

Thanks woodcock. It worked..

0 Karma

woodcock
Esteemed Legend

For benefit of everyone, please share the details of your solution. I am curious whether you got it in 1 combined search or 2.

0 Karma

renjith_nair
Legend

You can watch the file and alert whenever it changes. But why don't you do at the source itself. ie: since you are running a report/scheduled search to update the lookup, include this email alert part of your report itself. For eg: If the report returns any result , create an action to send an alert. Does this work for you?

http://docs.splunk.com/Documentation/Splunk/6.4.1/Alert/Emailnotification

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...