Alerting

Using tokens in email alerts to define a mailto address

clehw
Explorer

Hello! So i have an alert that emails out a report of productnames, their lifecyclestatus and the PrimaryPO, SecondaryPO and TertiaryPO (Product Owner)

I would like to create a token to pass to the "to" field of the email message where lifecyclestatus=newproduct to the PrimaryPO it can either be a batch email to send to multiple primarypo addresses for multiple lifecyclestatus=newproduct or a single email to each seperately... Does anyone have any ideas if this is doable? I hope i have explained that clearly enough.

Thanks in advance!

Carly

Please stay safe and healthy!

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...