Alerting

take SID in an alert

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I need to use SID as filename in an outputcsv command.
I reached to do this in a normal search

my_search
| ...
| addinfo
| outputcsv [ search * | head 1 | addinfo | eval query="my_alert_".info_sid | fields query | format "" "" "" "" "" "" ] singlefile=1

and I have a file called "my_search_1234567890.12345.csv".

The problem is when I schedule this search in an alert because the output csv is "my_search_schedule_admin.csv", in other words: running an alerts, instead SID I have the fixed string "schedule_admin".

Anyone has an idea where to search solution or (best) has a solution to solve the problem?

Thank you in advance.

Bye.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Just FYI, if you are using search head pooling or search head clustering then outputcsv is not compatible, see reference doc http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Outputcsv#Distributed_deployments

0 Karma

gcusello
SplunkTrust
SplunkTrust

None of them: it's a single Search Head!
Anyway, my search correctly runs in search mode, there's this strange behavior only running as alert.
Thanks.
Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

One additional information: I found that this problem there's only on a Windows machine, on a Linux machine I have the correct SID.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...