There are multiple different functions available for eval command. Example: | sendemail subject="Test " sendpdf=true priority=highest message="Please find attached latest search result" sendresults=trueĭEDUP: This command helps de-duplicate the results based upon specified fields, keeping the most recent match.ĮVAL: This command helps to evaluate new or existing fields and their values.the results, set the priority of the email, give a message i.e. ![]() For instance to whom you want to send the email, if you want to keep anyone in cc/bcc, change the subject line (by default its "Splunk Results"), sendpdf(true or false) i.e. you just need to pass a couple of values to it. SENDEMAIL: This command helps you to send an email straight away from the search head itself.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |