Live Splunks and Saved Splunks Configuration
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Live Splunks and Saved Splunks Configuration
These parameters configure Live Splunks and Saved Splunks
Filenames
- livesplunks.conf (within any subdirectory of $SPLUNK_HOME/etc/bundles/)
- savedsplunks.conf (within any subdirectory of $SPLUNK_HOME/etc/bundles/)
- liveSplunkMailer.sh (within the $SPLUNK_HOME/bin/ directory)
Format
[<spec>] attribute1 = val1 attribute2 = val2 ...
For more information, see the comments in the livesplunks.conf.spec and savedsplunks.conf.spec files.
Live Splunk Alert via Email
If you configured your Live Splunk to send email when its alert threshold has been met, the parameters of the email message are specified in $SPLUNK_HOME/bin/liveSplunkMailer.sh. To change the format of the message (subject, message body, etc.) simply edit this file. If you checked "Include results in email", the default method is to attach the search results in uuencoded form. This can also be modified by changing the way the searchresults.txt file is created in liveSplunkMailer.sh.
This documentation applies to the following versions of Splunk: 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.