<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error message gets truncated when alert email is sent in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331663#M10995</link>
    <description>&lt;P&gt;If you run the alert search manually and look at the field in question, is it getting parsed correctly there? It could be as simple as a misconfigured field extraction. &lt;/P&gt;</description>
    <pubDate>Fri, 08 Dec 2017 14:37:54 GMT</pubDate>
    <dc:creator>elliotproebstel</dc:creator>
    <dc:date>2017-12-08T14:37:54Z</dc:date>
    <item>
      <title>Error message gets truncated when alert email is sent</title>
      <link>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331662#M10994</link>
      <description>&lt;P&gt;Error message is of many lines for example this is one error message which we get when we use the same query on the search bar:&lt;BR /&gt;
ErrorMessage=The Event [CONFIRM] is not valid for the state [KITTING_COMPLETED]&lt;BR /&gt;
com.essilor.crimson.cosmic.store.exception.OrderTransitionException: The Event [CONFIRM] is not valid for the state [KITTING_COMPLETED]&lt;BR /&gt;
    at sun.reflect.GeneratedConstructorAccessor433.newInstance(Unknown Source)&lt;BR /&gt;
    at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)&lt;/P&gt;

&lt;P&gt;But when we set the alert we get only the first word in the message, Is there any limit on the alert email sent. please any idea.&lt;/P&gt;

&lt;P&gt;ErrorMessage=The&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331662#M10994</guid>
      <dc:creator>osubbu</dc:creator>
      <dc:date>2020-09-29T17:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Error message gets truncated when alert email is sent</title>
      <link>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331663#M10995</link>
      <description>&lt;P&gt;If you run the alert search manually and look at the field in question, is it getting parsed correctly there? It could be as simple as a misconfigured field extraction. &lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 14:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331663#M10995</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2017-12-08T14:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error message gets truncated when alert email is sent</title>
      <link>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331664#M10996</link>
      <description>&lt;P&gt;Look in the fields on the left side of the search.  Click on ErrorMessage.  See if "The" is a value shown there.  &lt;/P&gt;

&lt;P&gt;If so, this indicates that your parsing for field ErrorMessage is not set up correctly, and is stopping at the first space.&lt;/P&gt;

&lt;P&gt;So you need to update the conf that defines that extraction.  Post here when you have looked, and tell us what you see.  Then we can walk you through the fix.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 19:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331664#M10996</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-12-08T19:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error message gets truncated when alert email is sent</title>
      <link>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331665#M10997</link>
      <description>&lt;P&gt;Hi Daljeanis, Thanks for the reply and yes i see only the value "The" when i see under the interested fields as you suggested, error message extraction is stopping at the first space and displaying only that. can you please help me where i could fix this in which conf file.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 10:38:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-message-gets-truncated-when-alert-email-is-sent/m-p/331665#M10997</guid>
      <dc:creator>osubbu</dc:creator>
      <dc:date>2017-12-11T10:38:01Z</dc:date>
    </item>
  </channel>
</rss>

