<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Formatting alert emails in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41795#M523</link>
    <description>&lt;P&gt;I'll give that a try, thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 01 Sep 2010 22:43:32 GMT</pubDate>
    <dc:creator>Branden</dc:creator>
    <dc:date>2010-09-01T22:43:32Z</dc:date>
    <item>
      <title>Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41791#M519</link>
      <description>&lt;P&gt;The e-mail that an alert sends out isn't the prettiest e-mail in the world. It produces a pretty-wide HTML table with fields that we don't need. &lt;/P&gt;

&lt;P&gt;Is there a way to customize the e-mail output? I think someone asked a similar question on here a while ago, and the answer involved modifying a python script. I'd prefer not to go that route...&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2010 20:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41791#M519</guid>
      <dc:creator>Branden</dc:creator>
      <dc:date>2010-09-01T20:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41792#M520</link>
      <description>&lt;P&gt;There's no way to currently do this.  I have submitted an enhancement request for this.  If you submit one, it'll be more likely this feature gets added.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2010 20:45:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41792#M520</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2010-09-01T20:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41793#M521</link>
      <description>&lt;P&gt;Then I shall do so, thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2010 20:49:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41793#M521</guid>
      <dc:creator>Branden</dc:creator>
      <dc:date>2010-09-01T20:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41794#M522</link>
      <description>&lt;P&gt;As for removing fields, you should modify the search that generates the alert and add in the &lt;CODE&gt;fields fieldname1 fieldname2 ...&lt;/CODE&gt; search command (and maybe also &lt;CODE&gt;fields - _*&lt;/CODE&gt;) to select and order the fields you want included.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2010 22:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41794#M522</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-01T22:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41795#M523</link>
      <description>&lt;P&gt;I'll give that a try, thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2010 22:43:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41795#M523</guid>
      <dc:creator>Branden</dc:creator>
      <dc:date>2010-09-01T22:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Formatting alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41796#M524</link>
      <description>&lt;P&gt;You should try to edit the sendemail.py. Mails are created and sent by this script.&lt;/P&gt;

&lt;P&gt;The best way is to duplicate the script and modify all you want and use this script with your alert. I am working on the script to modify the format too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 16:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Formatting-alert-emails/m-p/41796#M524</guid>
      <dc:creator>woodreamz</dc:creator>
      <dc:date>2011-06-01T16:37:28Z</dc:date>
    </item>
  </channel>
</rss>

