<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change alert target email based on data in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180080#M3015</link>
    <description>&lt;P&gt;Update: Splunk 6.1 comes with this very feature &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2014 13:20:35 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-06-02T13:20:35Z</dc:date>
    <item>
      <title>Change alert target email based on data</title>
      <link>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180078#M3013</link>
      <description>&lt;P&gt;I would like to set up an alert that sends an email to an email address contained in the data that the alert triggers on. For example, let's say I have a data set that contains emails, and I want to count those and send those email addresses their counts every week or on some other timing. Can I somehow pipe the email field from the data that generated the alert into the email that is sent, instead of specifying the alert emails should always go to a static address I specify at the time I configure the alert?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 19:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180078#M3013</guid>
      <dc:creator>smileyge</dc:creator>
      <dc:date>2014-03-10T19:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Change alert target email based on data</title>
      <link>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180079#M3014</link>
      <description>&lt;P&gt;Splunk's alert emails can't do that out of the box. However, you can modify a copy of the sendemail command to roll your own email script that reads receivers from the data rather than from the alert config.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 21:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180079#M3014</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-10T21:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Change alert target email based on data</title>
      <link>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180080#M3015</link>
      <description>&lt;P&gt;Update: Splunk 6.1 comes with this very feature &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 13:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Change-alert-target-email-based-on-data/m-p/180080#M3015</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-06-02T13:20:35Z</dc:date>
    </item>
  </channel>
</rss>

