<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Passing result.&amp;lt;fieldname&amp;gt; token in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681198#M15826</link>
    <description>&lt;P&gt;I want my send email action email body to be in table view as my search result.&lt;BR /&gt;How do I pass dynamic token field value.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;$result.name$ $result.index$$result.sourcetype$&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;how do I make field value come side by side instead of below.&lt;BR /&gt;&amp;nbsp;how I am getting now in my email body&amp;nbsp;&lt;BR /&gt;name&lt;BR /&gt;name2&lt;BR /&gt;name3&lt;BR /&gt;name4&lt;BR /&gt;index&lt;BR /&gt;index2&lt;BR /&gt;index3&lt;BR /&gt;index4&lt;BR /&gt;sourcetype&lt;BR /&gt;sourcetype2&lt;BR /&gt;sourcetype3&lt;BR /&gt;sourcetype4&lt;BR /&gt;&lt;BR /&gt;I want to be like below.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;name index sourcetype
name2 index2 sourcetype2
name3 index3 sourcetype3
name4 index4 sourcetype4&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Is it possible to do&lt;/P&gt;</description>
    <pubDate>Sat, 23 Mar 2024 19:48:58 GMT</pubDate>
    <dc:creator>abi2023</dc:creator>
    <dc:date>2024-03-23T19:48:58Z</dc:date>
    <item>
      <title>Passing result.&lt;fieldname&gt; token</title>
      <link>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681198#M15826</link>
      <description>&lt;P&gt;I want my send email action email body to be in table view as my search result.&lt;BR /&gt;How do I pass dynamic token field value.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;$result.name$ $result.index$$result.sourcetype$&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;how do I make field value come side by side instead of below.&lt;BR /&gt;&amp;nbsp;how I am getting now in my email body&amp;nbsp;&lt;BR /&gt;name&lt;BR /&gt;name2&lt;BR /&gt;name3&lt;BR /&gt;name4&lt;BR /&gt;index&lt;BR /&gt;index2&lt;BR /&gt;index3&lt;BR /&gt;index4&lt;BR /&gt;sourcetype&lt;BR /&gt;sourcetype2&lt;BR /&gt;sourcetype3&lt;BR /&gt;sourcetype4&lt;BR /&gt;&lt;BR /&gt;I want to be like below.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;name index sourcetype
name2 index2 sourcetype2
name3 index3 sourcetype3
name4 index4 sourcetype4&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Is it possible to do&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2024 19:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681198#M15826</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2024-03-23T19:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Passing result.&lt;fieldname&gt; token</title>
      <link>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681463#M15844</link>
      <description>&lt;P&gt;In Email alerts, there is a checkbox for "Inline", which would put the search results table into the body of the email.&lt;/P&gt;&lt;P&gt;If you would like more control over it, you could do some SPL magic to make a single field containing the html for a table in the arrangement you want, then put that field in the body.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 21:52:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681463#M15844</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-20T21:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Passing result.&lt;fieldname&gt; token</title>
      <link>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681632#M15847</link>
      <description>&lt;P&gt;Can this work for passing value to Splunk add on for Servicenow. Description section.&lt;BR /&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 00:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681632#M15847</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2024-03-22T00:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Passing result.&lt;fieldname&gt; token</title>
      <link>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681752#M15853</link>
      <description>&lt;P&gt;I don't have experience with that particular app but in theory it should work. Give it a try!&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2024 16:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Passing-result-lt-fieldname-gt-token/m-p/681752#M15853</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-23T16:34:53Z</dc:date>
    </item>
  </channel>
</rss>

