Splunk Search

Can I have multiple CSVs emailed to me through a single alert?

sarwshai
Communicator

I have created more than 10 alerts for different trigger conditions which send a unique CSV through mail, For e.g. there is field 'Country' in which many countries come and I have set different alerts just to segregate countries but the core search is exactly same of all alerts and each Country CSV file comes in different email
And of course, I can set in one single alert, the question is can I have multiple CSVs emailed to me through that single alert?

0 Karma

horsefez
Motivator

Hi sarwshai,

I think you might need to look at custom alert actions for this case.
http://docs.splunk.com/Documentation/Splunk/7.0.2/AdvancedDev/ModAlertsIntro

Heavy scripting ahead. IMO.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...