Splunk Cloud

Search Reference

Download manual as PDF

Download topic as PDF



For Splunk Enterprise deployments, executes scripted alerts. This command is not supported as a search command.


runshellscript <script-filename> <result-count> <search-terms> <search-string> <savedsearch-name> <description> <results-url> <deprecated-arg> <results_file>


The script file needs to be located in either $SPLUNK_HOME/etc/system/bin/scripts OR $SPLUNK_HOME/etc/apps/<app-name>/bin/scripts. The following table describes the arguments passed to the script. These arguments are not validated.

Argument Description
$0 The filename of the script.
$1 The result count, or number of events returned.
$2 The search terms.
$3 The fully qualified query string.
$4 The name of the saved search in Splunk.
$5 The description or trigger reason. For example, "The number of events was greater than 1."
$6 The link to saved search results.
$7 DEPRECATED - empty string argument.
$8 The path to the results file, results.csv. The results file contains raw results.

See also



Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the runshellscript command.


This documentation applies to the following versions of Splunk Cloud: 6.5.0, 6.5.1, 6.5.1612, 6.6.0, 6.6.1, 6.6.3


"$0 = The filename of the script." Is not actually passed to the script. E.g. in perl, $ARGV[0] is the result count .. $ARGV[7] is the results file. In bash, $0 is the currently executing script name, so the indices shown here are correct.

November 4, 2012

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters