<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to make fields show in an alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683715#M15904</link>
    <description>&lt;P&gt;If you edit your earlier answer to correct the syntax, I'll be able to mark it as the solution...&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 16:10:53 GMT</pubDate>
    <dc:creator>unitedmarsupial</dc:creator>
    <dc:date>2024-04-09T16:10:53Z</dc:date>
    <item>
      <title>How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683691#M15899</link>
      <description>&lt;P&gt;I have an alert based on the below search (obfuscated):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;...
| eval APPDIR=source
| rex field=APPDIR mode=sed "s|/logs\/.*||g"
| eventstats values(APPDIR) as APPDIRS
| eval Level=if("/app/5000" IN (APPDIRS), "PRODUCTION", "Non-production")
| eval APPDIRS=mvjoin(APPDIRS, ",")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea is to discern the affected application-instance (there are multiple logs under each of the &lt;FONT face="courier new,courier"&gt;/app/&lt;EM&gt;instance&lt;/EM&gt;/logs/&lt;/FONT&gt;) and then to determine, whether the instance is a production one or not. In the search-results all three new fields (APPDIR, APPDIRS, and Level) are populated as expected.&lt;/P&gt;&lt;P&gt;But they don't show up in the e-mails. The "&lt;FONT face="courier new,courier"&gt;Subject: $Level$ app in $APPDIRS$&lt;/FONT&gt;" expands to mere "&lt;FONT face="courier new,courier"&gt;Subject:&amp;nbsp; app in&lt;/FONT&gt; ". Nor are the fields expanded in the body of the alert e-mail.&lt;/P&gt;&lt;P&gt;Now, I understand, that event-specific fields -- like the singular APPDIR above -- cannot be expected to work in an alert. But the plural APPDIRS, as well as the Level, are aggregates, aren't they?&lt;/P&gt;&lt;P&gt;What am I doing wrong, and how do I fix it?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 14:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683691#M15899</guid>
      <dc:creator>unitedmarsupial</dc:creator>
      <dc:date>2024-04-09T14:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683694#M15900</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/EmailNotificationTokens#Result_tokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/EmailNotificationTokens#Result_tokens&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 14:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683694#M15900</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-09T14:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683696#M15901</link>
      <description>&lt;P&gt;Have you tried &lt;FONT face="courier new,courier"&gt;"Subject: $result.Level$ app in $result.APPDIRS$"&lt;FONT face="arial,helvetica,sans-serif"&gt;?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683696#M15901</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-09T16:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683711#M15902</link>
      <description>&lt;P&gt;Oh, I see... But &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/EmailNotificationTokens#Result_tokens" target="_blank" rel="noopener"&gt;should not it be&lt;/A&gt; $result.Level$ -- that is, singular "result", not plural "results"? Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683711#M15902</guid>
      <dc:creator>unitedmarsupial</dc:creator>
      <dc:date>2024-04-09T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683712#M15903</link>
      <description>&lt;P&gt;You are correct.&amp;nbsp; Use the singular form.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:47:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683712#M15903</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-09T15:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683715#M15904</link>
      <description>&lt;P&gt;If you edit your earlier answer to correct the syntax, I'll be able to mark it as the solution...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683715#M15904</guid>
      <dc:creator>unitedmarsupial</dc:creator>
      <dc:date>2024-04-09T16:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to make fields show in an alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683718#M15905</link>
      <description>&lt;P&gt;Done&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-make-fields-show-in-an-alert/m-p/683718#M15905</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-09T16:32:21Z</dc:date>
    </item>
  </channel>
</rss>

