So, what happens when an alert fires in Splunk? Well, that is up to you, as Splunk offers several possible Trigger Actions out of the box, and these are detailed in the following table:
Trigger action |
Description |
Send Email |
This sends an email to one or more specified individuals together with details of the alert that has fired. This email can be substantially customized in Version 6 and is probably the most commonly used action. |
Run a script |
This invokes and executes a custom script when the alert is triggered and provides a very powerful functionality. For example, you might have a script that opens a ticket in a third-party ticketing system when an alert is triggered. Note: The run a script alert ... |