Alert Trigger Actions

So, what happens when an alert fires in Splunk? Well, that is up to you, as Splunk offers several possible Trigger Actions out of the box, and these are detailed in the following table:

Trigger action

Description

Send Email

This sends an email to one or more specified individuals together with details of the alert that has fired. This email can be substantially customized in Version 6 and is probably the most commonly used action.

Run a script

This invokes and executes a custom script when the alert is triggered and provides a very powerful functionality. For example, you might have a script that opens a ticket in a third-party ticketing system when an alert is triggered.

Note: The run a script alert ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.