Alerting

Why does the output for triggered alert scripts in Splunk contain ^ (hats/caret) characters?

ss250858
Observer

I am calling a script on a triggered alert to send an snmp trap, but it was coming across like this.

"index^=common^ sourcetype^=processor^ source^=*Online*^ ^(REQ^ OR^ RSP^)^ earliest^=-5m@m^ latest^=now^ ^

I thought it was something snmp was doing but i redirected the output via a batch script and it's coming directly from Splunk as the values being passed.

What would be causing these?

0 Karma

cmisztur
Explorer

good question...

0 Karma

rodrigorsilva
Communicator

Hi,

Saw this - hope its useful:

https://answers.splunk.com/answers/68372/generate-snmp-trap-from-splunk.html

This script is very used, I use it myself and never had problems.

Tks

Rodrigo Ribeiro

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...