Hello all. New to splunk. How can I perform a SendEmail for each log that comes in, which will have a different email address for each?
index=wm_xsp_cad host=vxxx0u8997 "inactive team" index=wm_xsp_cad host=vxxx30u8997 "Inactive team"|table TeamEmail, ECI, CADesc | eval valueForToHeader=TeamEmail | sendemail
sendresults=true inline=true
to= ????
Subject=\"$CADesc\$\"
From="james@jL.com"
Subject="hello"
server= localhost
graceful=false
Thank you, this is helpful
Take a look at the Sendresults search command: https://splunkbase.splunk.com/app/1794/
Making some progress with this however I need assistance with sending one email per record, rather than one email for all the records?
index=wm_xsp_cad host=vxxx0u8997 "inactive team" index=wm_xsp_cad host=vxxx30u8997 "Inactive team"|table TeamEmail, ECI, CADesc | eval valueForToHeader=TeamEmail | sendemail
sendresults=true inline=true
to= ????
Subject=\"$CADesc\$\"
From="james@jL.com"
Subject="hello"
server= localhost
graceful=false