Does anyone have a sample alert script that, once triggered, takes the data set handle passed to it from the Splunk alert, opens up the csv.gz events file, processes the resulting events, and formats and send an snmp message (that includes results, etc) to a monitoring system?
Anything anyone would care to share along these lines would be greatly appreciated.
I wrote a PHP program that did something very similar. If you know PHP might be a quick hack and smash to pull out what you need. It's posted on splunkbase.
http://www.splunkbase.com/apps/All/4.x/Add-On/app:PHP+Scripted+Alerts