<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data missing in Alert search in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549705#M10452</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233954"&gt;@MScottFoley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see &lt;STRONG&gt;$name$&lt;/STRONG&gt; for the alerts in the GUI, or do you see &lt;STRONG&gt;Splunk Alert: $name$&lt;/STRONG&gt;? The default subject values come from $SPLUNK_HOME/etc/system/default/alert_actions.conf:&lt;/P&gt;&lt;P&gt;[email]&lt;BR /&gt;# ...&lt;BR /&gt;subject = Splunk Alert: $name$&lt;BR /&gt;subject.alert = Splunk Alert: $name$&lt;BR /&gt;subject.report = Splunk Report: $name$&lt;/P&gt;</description>
    <pubDate>Wed, 28 Apr 2021 23:13:56 GMT</pubDate>
    <dc:creator>tscroggins</dc:creator>
    <dc:date>2021-04-28T23:13:56Z</dc:date>
    <item>
      <title>Data missing in Alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549689#M10451</link>
      <description>&lt;P&gt;I am doing an audit on Splunk alerts.&amp;nbsp; One of the things I am looking for is if the Alert name is in the subject of the email that gets sent.&amp;nbsp; &amp;nbsp;I run the search at the bottom of this message and parse that.&amp;nbsp; There are hundreds of alerts and most of them have one of these two settings.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"action.email.subject.alert": "$name$"&lt;BR /&gt;"action.email.subject": "$name$"&lt;/P&gt;&lt;P&gt;I don't know the difference between the two, but they seem to match proper alert setups in the GUI.&amp;nbsp; There are a few dozen alerts that don't return either of these though.&amp;nbsp; When I look at one of those alerts in the GUI it has the correct setting for the alert.&amp;nbsp; &amp;nbsp;The email subject is $name$.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't these Alerts that seem to be configured correctly return the&amp;nbsp;"action.email.subject" field?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have even run the search where I return all fields and can't find another that looks like it would be the subject field.&lt;/P&gt;&lt;P&gt;Search:&lt;BR /&gt;|rest/servicesNS/-/-/saved/searches | search alert.track=1&lt;BR /&gt;| fields title Action.email.to Action.email.subject Action.email.subject.alert&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk 7.3.3&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 20:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549689#M10451</guid>
      <dc:creator>MScottFoley</dc:creator>
      <dc:date>2021-04-28T20:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data missing in Alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549705#M10452</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233954"&gt;@MScottFoley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see &lt;STRONG&gt;$name$&lt;/STRONG&gt; for the alerts in the GUI, or do you see &lt;STRONG&gt;Splunk Alert: $name$&lt;/STRONG&gt;? The default subject values come from $SPLUNK_HOME/etc/system/default/alert_actions.conf:&lt;/P&gt;&lt;P&gt;[email]&lt;BR /&gt;# ...&lt;BR /&gt;subject = Splunk Alert: $name$&lt;BR /&gt;subject.alert = Splunk Alert: $name$&lt;BR /&gt;subject.report = Splunk Report: $name$&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 23:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549705#M10452</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2021-04-28T23:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data missing in Alert search</title>
      <link>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549844#M10453</link>
      <description>&lt;P&gt;I looked at a couple that were not showing up and they did have "&lt;SPAN&gt;Splunk Alert: $name$" as the subject.&amp;nbsp; &amp;nbsp;When I looked at the output from the search I did not see any with&amp;nbsp;Splunk Alert: $name$.&amp;nbsp; This leads me to believe that any alert missing&amp;nbsp;the value is set to the default.&amp;nbsp; &amp;nbsp;I'll do a couple of tests to see it that holds true.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Data-missing-in-Alert-search/m-p/549844#M10453</guid>
      <dc:creator>MScottFoley</dc:creator>
      <dc:date>2021-04-29T13:59:44Z</dc:date>
    </item>
  </channel>
</rss>

