<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does $result.fieldname$ token not work in alert emails? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231175#M4311</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Looks like this still does not work in 7.0.&lt;/P&gt;

&lt;P&gt;Another workaround that worked for me to resolve an empty token $result.Value$ in the message is putting Value=* in the search.&lt;/P&gt;

&lt;P&gt;source="Perfmon:Schijfruimte" host="rivm-sf-0107" index="perfmon" counter="Free Megabytes" instance=D: Value=*&lt;/P&gt;

&lt;P&gt;Best regards,&lt;/P&gt;

&lt;P&gt;Jan  ,Looks like this problem still exists in 7.0 &lt;/P&gt;

&lt;P&gt;Another workaround that worked for me to solve the empty token $result.Value$ in the message is adding this to the search:  Value=*&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Jan&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 10:00:04 GMT</pubDate>
    <dc:creator>schollaert</dc:creator>
    <dc:date>2017-10-16T10:00:04Z</dc:date>
    <item>
      <title>Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231170#M4306</link>
      <description>&lt;P&gt;As specified here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1/Alert/Setupalertactions#Use_tokens_in_email_notifications"&gt;http://docs.splunk.com/Documentation/Splunk/6.1/Alert/Setupalertactions#Use_tokens_in_email_notifications&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;it should be possible to use a field from the event that caused the alert by typing &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$result.&amp;lt;fieldname&amp;gt;$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This works fine for standard fields, e.g. $result.host$. But, with customer fields, it does not seem to work. For example, the event that triggers the alert has a field named "AppName". When I specify &lt;CODE&gt;$result.AppName$&lt;/CODE&gt; in the e-mail subject, it is substituted with an empty string as if that field did not exist.&lt;/P&gt;

&lt;P&gt;Any ideas why?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 08:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231170#M4306</guid>
      <dc:creator>dmytro_gokun</dc:creator>
      <dc:date>2016-01-13T08:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231171#M4307</link>
      <description>&lt;P&gt;Hi @dmytro_gokun&lt;/P&gt;

&lt;P&gt;Does the answer in this question explain/apply to the issue you're seeing? &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/326179/i-want-to-use-result-in-my-alert-messages-but-it-d.html"&gt;https://answers.splunk.com/answers/326179/i-want-to-use-result-in-my-alert-messages-but-it-d.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 01:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231171#M4307</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-01-14T01:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231172#M4308</link>
      <description>&lt;P&gt;Hi Pablo,&lt;/P&gt;

&lt;P&gt;well, it kind of related, but i'm not sure if it's 100% my case.&lt;BR /&gt;
What i have as the alert's source is a simple search without any "transforming commands". So, it looks pretty strange that some fields are absent from that. I might be wrong here, but it looks like a bug in Splunk to me. What do you think? Should we report a bug?&lt;/P&gt;

&lt;P&gt;I managed to make fields available by piping the search results into the "fields" command listing all the fields i need. It's a bit clumsy work-around, but it does the trick.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Dmytro.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 07:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231172#M4308</guid>
      <dc:creator>dmytro_gokun</dc:creator>
      <dc:date>2016-01-14T07:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231173#M4309</link>
      <description>&lt;P&gt;Hi @dmytro_gokun&lt;/P&gt;

&lt;P&gt;Thanks for sharing your workaround for others to try out. If other users don't come along this post to help dig deeper into what the problem is, then it won't hurt to submit it as a bug here &lt;A href="http://www.splunk.com/r/bugs"&gt;http://www.splunk.com/r/bugs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you find out anything, either an explanation of the unexpected behavior or confirmation that it's a bug, please update this post as it'd be helpful for other folks to be aware of. &lt;/P&gt;

&lt;P&gt;@davidpaper, do you think you'd be able to chime in on this post?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 21:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231173#M4309</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-01-19T21:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231174#M4310</link>
      <description>&lt;P&gt;Is there a user tool to lookup bugs that have been submitted to splunk?  This definitely feels like a bug, but I don't want to submit duplicates, there are a few bugs that I am still waiting on. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;If this isn't already in their buglist, I am happy to create one.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 00:07:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231174#M4310</guid>
      <dc:creator>jgoddard</dc:creator>
      <dc:date>2016-09-13T00:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231175#M4311</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Looks like this still does not work in 7.0.&lt;/P&gt;

&lt;P&gt;Another workaround that worked for me to resolve an empty token $result.Value$ in the message is putting Value=* in the search.&lt;/P&gt;

&lt;P&gt;source="Perfmon:Schijfruimte" host="rivm-sf-0107" index="perfmon" counter="Free Megabytes" instance=D: Value=*&lt;/P&gt;

&lt;P&gt;Best regards,&lt;/P&gt;

&lt;P&gt;Jan  ,Looks like this problem still exists in 7.0 &lt;/P&gt;

&lt;P&gt;Another workaround that worked for me to solve the empty token $result.Value$ in the message is adding this to the search:  Value=*&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 10:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231175#M4311</guid>
      <dc:creator>schollaert</dc:creator>
      <dc:date>2017-10-16T10:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231176#M4312</link>
      <description>&lt;P&gt;Even when I include the Value=* in the search, I am not able to get the token in Subject Line.&lt;/P&gt;

&lt;P&gt;An interesting thing is - I am able to get the $result.Value$ in the message body but not Subject &lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 21:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231176#M4312</guid>
      <dc:creator>snaikwade_splun</dc:creator>
      <dc:date>2017-11-14T21:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231177#M4313</link>
      <description>&lt;P&gt;On 6.5.3 I had to add Value=* for it to show up in either Subject or Body. It seems it is acting the same way many RESTful calls do. You have to explicitly specify which fields to return otherwise they won't be there.  &lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 15:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231177#M4313</guid>
      <dc:creator>ifeldshteyn</dc:creator>
      <dc:date>2019-06-19T15:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why does $result.fieldname$ token not work in alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231178#M4314</link>
      <description>&lt;P&gt;You stated that this happens with your custom fields.&lt;/P&gt;

&lt;P&gt;However, I do not think it is an issue with your custom fields, as I do not have a problem doing this with my custom fields if I do not &lt;CODE&gt;table&lt;/CODE&gt;. Yet I do have a problem doing this with my &lt;CODE&gt;table&lt;/CODE&gt; command. I'm willing to wager you used a table or a chart. I think this is a bug.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/793094/can-you-put-a-non-tabled-field-in-an-alert-title.html"&gt;https://answers.splunk.com/answers/793094/can-you-put-a-non-tabled-field-in-an-alert-title.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 21:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-result-fieldname-token-not-work-in-alert-emails/m-p/231178#M4314</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2020-01-08T21:13:02Z</dc:date>
    </item>
  </channel>
</rss>

