Hello,
Is there is any way to send email whenever there is a change in a lookup?
I have a report which updates the lookup whenever there is a breach in threshold. I wanted to send an email whenever that lookup gets updated. Is there any way to do that?
You can schedule a search that uses inputlookup
to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup
to contain the updated original's data. This can all be done in a single search using sendemail
.
You can schedule a search that uses inputlookup
to copy the file and compare it to the a copy. Whenever what you read that the original is different from the copy, send an email, then update the copy with outputlookup
to contain the updated original's data. This can all be done in a single search using sendemail
.
Thanks woodcock. It worked..
For benefit of everyone, please share the details of your solution. I am curious whether you got it in 1 combined search or 2.
You can watch the file and alert whenever it changes. But why don't you do at the source itself. ie: since you are running a report/scheduled search to update the lookup, include this email alert part of your report itself. For eg: If the report returns any result , create an action to send an alert. Does this work for you?
http://docs.splunk.com/Documentation/Splunk/6.4.1/Alert/Emailnotification