Hi ALL!
sourcetye=error | stats count by email | sendmail to=....
I want the receiver in "sendmail" is the result of query "stats count by email"
For example:
If we have 3 emails from the "stats count by email"
Then the query "sendmail" will send email to the 3 above emails.
Thanks in advance!
Hi vumanhtai,
You may want to take a look at this app which allows for more dynamic alerting based on results: https://splunkbase.splunk.com/app/1794/#/details.
Try this:
sourcetype=error | stats count by email | sendmail to=$result.email$
OR
sourcetype=error | stats count by email | sendmail to=$email$