Splunk Search

Can I have multiple CSVs emailed to me through a single alert?

sarwshai
Communicator

I have created more than 10 alerts for different trigger conditions which send a unique CSV through mail, For e.g. there is field 'Country' in which many countries come and I have set different alerts just to segregate countries but the core search is exactly same of all alerts and each Country CSV file comes in different email
And of course, I can set in one single alert, the question is can I have multiple CSVs emailed to me through that single alert?

0 Karma

horsefez
SplunkTrust
SplunkTrust

Hi sarwshai,

I think you might need to look at custom alert actions for this case.
http://docs.splunk.com/Documentation/Splunk/7.0.2/AdvancedDev/ModAlertsIntro

Heavy scripting ahead. IMO.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...