<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215085#M3839</link>
    <description>&lt;P&gt;Hi @Roopaul,&lt;BR /&gt;
Here is what I would suggest:&lt;BR /&gt;
1) Set up scheduled reports that run this query for each component (not sure how many components you anticipate)&lt;BR /&gt;
2) Set up an email action for those reports so that you get emails when the scheduled report is done. You can include information from the search results in the alert emails.&lt;/P&gt;

&lt;P&gt;Here is some documentation on using scheduled reports:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps! Let me know if not and we can continue discussing.&lt;/P&gt;

&lt;P&gt;All best,&lt;BR /&gt;
@frobinson_splunk&lt;/P&gt;</description>
    <pubDate>Fri, 04 Sep 2015 23:26:25 GMT</pubDate>
    <dc:creator>frobinson_splun</dc:creator>
    <dc:date>2015-09-04T23:26:25Z</dc:date>
    <item>
      <title>How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215082#M3836</link>
      <description>&lt;P&gt;I created a search which displays below results:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Server   component   Proxy   Count
   A        AB        ABC      2
   A        AB        ABD      4
   A        AC        ABC      2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I need to send an email for each component i.e.&lt;BR /&gt;
Email 1:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Server   component   Proxy   Count
   A        AB        ABC      2
   B        AB        ABD      4
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Email 2:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Server   component   Proxy   Count
   A        AC        ABC      2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Can someone help?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 22:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215082#M3836</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2015-09-04T22:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215083#M3837</link>
      <description>&lt;P&gt;Hi @Roopaul,&lt;BR /&gt;
I'm a tech writer here at Splunk and I work on alerting documentation. I am looking into this and will post some documentation resources that should help. I'll report back shortly!&lt;BR /&gt;
All best,&lt;BR /&gt;
@frobinson_splunk&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 23:09:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215083#M3837</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-09-04T23:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215084#M3838</link>
      <description>&lt;P&gt;Great. That will be really helpful. Looking forward to it.&lt;/P&gt;

&lt;P&gt;Do you have any high level date on when this will be available as i am working on an urgent requirement.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 23:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215084#M3838</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2015-09-04T23:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215085#M3839</link>
      <description>&lt;P&gt;Hi @Roopaul,&lt;BR /&gt;
Here is what I would suggest:&lt;BR /&gt;
1) Set up scheduled reports that run this query for each component (not sure how many components you anticipate)&lt;BR /&gt;
2) Set up an email action for those reports so that you get emails when the scheduled report is done. You can include information from the search results in the alert emails.&lt;/P&gt;

&lt;P&gt;Here is some documentation on using scheduled reports:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Report/Schedulereports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps! Let me know if not and we can continue discussing.&lt;/P&gt;

&lt;P&gt;All best,&lt;BR /&gt;
@frobinson_splunk&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 23:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215085#M3839</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2015-09-04T23:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215086#M3840</link>
      <description>&lt;P&gt;Do you need to send to different email addresses based on the component?  Or just fire separate emails but all to the same address?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2015 21:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215086#M3840</guid>
      <dc:creator>justinatpnnl</dc:creator>
      <dc:date>2015-09-05T21:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215087#M3841</link>
      <description>&lt;P&gt;@frobinson_splunk&lt;BR /&gt;
I am doing scheduled reports for this alert. But my requirement is I want to send an email based on the output of the query (see my example above).&lt;/P&gt;

&lt;P&gt;@justinatpnnl - The recipents are going to be the same. the email content will vary based on the output as i mentioned above.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 17:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215087#M3841</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2015-09-08T17:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215088#M3842</link>
      <description>&lt;P&gt;What if you tried something like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| stats list(Server) as Server, list(Proxy) as Proxy, list(Count) as Count by Component&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;That would give you something like this as a result, where each component has its own row (this may not display correctly below, but hopefully you get the idea):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Component   Server  Proxy   Count
AB         A         ABC      2
             B       ABD      4
AC         A         ABC      2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now you can save this as an alert and fire "For each result".   Would that work for you?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 18:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215088#M3842</guid>
      <dc:creator>justinatpnnl</dc:creator>
      <dc:date>2015-09-08T18:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215089#M3843</link>
      <description>&lt;P&gt;@justinatpnnl&lt;/P&gt;

&lt;P&gt;this is great. Yes this will defintely work for me. I was unaware of "list" argument and was using "values". Thanks a lot!!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 18:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215089#M3843</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2015-09-08T18:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215090#M3844</link>
      <description>&lt;P&gt;For this described method, how do I make each multivalued field show up on a new line instead of bunched together on one line in an email alert with an Inline Table? &lt;/P&gt;

&lt;P&gt;For example, I want the table in the email to show up like the table described in the answer. However, in my emails, I'm getting a table with "A" and "B" showing up as "A B" on one line instead of a separate row for server "B". &lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 18:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215090#M3844</guid>
      <dc:creator>jamestoan</dc:creator>
      <dc:date>2015-09-21T18:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215091#M3845</link>
      <description>&lt;P&gt;Yes, we also faced the same issue and it looks like a limitation with splunk. In the email the field size is determined as per the width of the column heading. So what we did is we manipulated the column width by adding spaces to the column name (it should be higher than the result's highest length):&lt;BR /&gt;
For eg.&lt;BR /&gt;
|eval server= server."                                                                    "|&lt;BR /&gt;&lt;BR /&gt;
Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 19:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/215091#M3845</guid>
      <dc:creator>Roopaul</dc:creator>
      <dc:date>2015-09-21T19:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a custom alert condition to send multiple email alerts with different results based on a certain field?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/584689#M13462</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for the same use case, have you find an solution for that ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 10:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-set-a-custom-alert-condition-to-send-multiple-email/m-p/584689#M13462</guid>
      <dc:creator>miguel1423</dc:creator>
      <dc:date>2022-02-11T10:16:03Z</dc:date>
    </item>
  </channel>
</rss>

