Is there any way for Splunk alerts to create a CSV or txt file with only hostname and error message values? How can I export those to CSV (need an output file).
Have your tried the Scheduled Export of Indexed Data (SEND) to File alert action? https://splunkbase.splunk.com/app/2914/ Needs 6.3+.