<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send table format query result from splunk to slack in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641843#M445</link>
    <description>&lt;P&gt;It really depends on what you want to achieve but the easiest thing for starters would be to do&lt;/P&gt;&lt;PRE&gt;| stats values(*) as *&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Apr 2023 18:49:30 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-04-30T18:49:30Z</dc:date>
    <item>
      <title>How to send table format query result from Splunk to Slack?</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641831#M442</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-30 at 12.40.33 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25145i69D34A7A8D3E5A3F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-04-30 at 12.40.33 PM.png" alt="Screenshot 2023-04-30 at 12.40.33 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a requirement where i want send the above query result from splunk to slack as an FYI alert. But somehow i am not able to achieve it and i am unable find the right documents to processed. I did try to print using&amp;nbsp; $result.req$&amp;nbsp;$result.method$ and&amp;nbsp;$result.percentile99$ but i get to see the slack message for just 1st row.&amp;nbsp;&lt;BR /&gt;But i would need the complete query to be shown in slack message. How do i achieve this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;@&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168" target="_self"&gt;&lt;SPAN class=""&gt;ITWhisperer&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;or anyone please help me out here&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 11:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641831#M442</guid>
      <dc:creator>skumarr</dc:creator>
      <dc:date>2023-05-01T11:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Send table format query result from splunk to slack</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641834#M443</link>
      <description>&lt;P&gt;I don't know this particular add-on so I'm only speculating here but it is possible that the action allows only sending a single row from the results. In that case you'd have to either modify the script to include more rows (which might be tricky and will give you additional maintenance burden in the future) or you can rework your search to return values in a single row (possibly using multivalued fields)&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2023 08:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641834#M443</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-04-30T08:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Send table format query result from splunk to slack</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641836#M444</link>
      <description>&lt;P&gt;Can you help me with some examples&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; on how to return list of rows into 1 single row and get that displayed in slack&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2023 09:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641836#M444</guid>
      <dc:creator>skumarr</dc:creator>
      <dc:date>2023-04-30T09:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Send table format query result from splunk to slack</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641843#M445</link>
      <description>&lt;P&gt;It really depends on what you want to achieve but the easiest thing for starters would be to do&lt;/P&gt;&lt;PRE&gt;| stats values(*) as *&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2023 18:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641843#M445</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-04-30T18:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Send table format query result from splunk to slack</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641846#M446</link>
      <description>&lt;P&gt;Yes so you can only refer to field names but not get multiple values of a field so you need to use stats or eval to create the fields you want&amp;nbsp;&lt;/P&gt;&lt;P&gt;So like &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;suggests&amp;nbsp;&lt;/P&gt;&lt;P&gt;stats values(*) AS *&lt;/P&gt;&lt;P&gt;And then use the actual fieldname in the body of the Slack alert eg $yourfield$&lt;/P&gt;&lt;P&gt;Here are more ideas&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-custom-alert-message-with-variables/m-p/438380#M174048" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-custom-alert-message-with-variables/m-p/438380#M174048&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2023 21:02:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-send-table-format-query-result-from-Splunk-to-Slack/m-p/641846#M446</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2023-04-30T21:02:37Z</dc:date>
    </item>
  </channel>
</rss>

