January 2013
Beginner to intermediate
448 pages
9h 16m
English
Another option for interfacing with an external system is to run a custom Alert action using the results of a saved search. Splunk provides a simple example in $SPLUNK_HOME/bin/scripts/echo.sh. Let's try it out and see what we get, using the following steps:
index=_internal | head 100 | stats count by sourcetype
echo.sh.
The script places the output into $SPLUNK_HOME/bin/scripts/echo_output.txt ...
Read now
Unlock full access