All Apps and Add-ons

Is it possible for a report to be triggered like an alert?

omuelle1
Communicator

Splunkers,

I have a question regarding a report:

We made a report with 15 searches that is being to delivered to a different team once a day as a PDF. However, often times, all the searches in the report don't have any results, so we are wondering if the report can also be triggered like an alert only if it has at least one result?

So far I only came up with the idea to just make 15 individual alerts instead of a report. Is there an easier way to do this? I cannot combine all searches into one alert since I use Splunk DB Connect and query different schemas and databases in the searches.

Thank you,

Oliver

0 Karma
1 Solution

niketn
Legend

You can try saving the Report as Scheduled Report which runs on scheduled basis and then choose alert action on the scheduled report to send out emails. Refer to following documentation on Scheduled report and how to setup the same:

http://docs.splunk.com/Documentation/Splunk/latest/Report/Schedulereports#Schedule_reports_in_Settin...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

You can try saving the Report as Scheduled Report which runs on scheduled basis and then choose alert action on the scheduled report to send out emails. Refer to following documentation on Scheduled report and how to setup the same:

http://docs.splunk.com/Documentation/Splunk/latest/Report/Schedulereports#Schedule_reports_in_Settin...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

omuelle1
Communicator

Thank you!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...