Include sendcsv parameter for email alert action
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 38/100
Research direction
Start by locating the Jinja2 template that renders deployment.alert_action.email and trace how the YAML sendcsv value is loaded. Done means a true sendcsv setting produces the requested action.email.sendcsv output, with coverage for the enabled and unset cases.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
Allow the results to be attached as CSV when this option is enabled for the email alert action.
Describe the solution you'd like
When the sendcsv key is defined as 'true':
deployment:
alert_action:
email:
sendcsv: 'true'
, then it's set through the jinja2 template:
{% if detection.deployment.alert_action.email.sendcsv %}
action.email.sendcsv = 1
{% endif %}
Describe alternatives you've considered
We can of course set it through the Spunk UI or REST API, but the preference is to use DaC as much as possible.
Additional context
N/A
- Dominant language
- Python
- Stars
- 139
- Forks
- 52
- Avg merge
- 1h 16m
- Merged PRs (30d)
- 3
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from splunk/contentctl
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 45/100
splunk/contentctl#468 · 1 comment ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 38/100
splunk/contentctl#461 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 48/100
splunk/contentctl#452 ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
splunk/contentctl#464 · 3 comments ·
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
splunk/contentctl#451 ·
All issues in splunk/contentctl
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100