<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you properly format Splunk email alerts? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-you-properly-format-Splunk-email-alerts/m-p/450331#M7920</link>
    <description>&lt;P&gt;Hi @samsam48,&lt;/P&gt;

&lt;P&gt;By &lt;CODE&gt;$result.fieldName$&lt;/CODE&gt; you are referring to the message field. If you want to put the entire result in the email content, you can use the &lt;CODE&gt;Include&lt;/CODE&gt; option  - the 7th option mentioned in the following documentation &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Emailnotification#Define_an_email_notification_for_an_alert_or_scheduled_report"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Emailnotification#Define_an_email_notification_for_an_alert_or_scheduled_report&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also you could opt to just add the  link to the results or add as a PDF/csv attachments.&lt;/P&gt;

&lt;P&gt;Hope that helps for your requirement&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 14:36:42 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2018-09-06T14:36:42Z</dc:date>
    <item>
      <title>How do you properly format Splunk email alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-you-properly-format-Splunk-email-alerts/m-p/450330#M7919</link>
      <description>&lt;P&gt;I'm new to Splunk, and I'm having a hard time understanding how to properly format Splunk Email Alerts. I understand that we're able to pull information from the search results to include in the email body (like a field name with: &lt;CODE&gt;$result.fieldName$&lt;/CODE&gt;). However, this is limited to the first value of the first row of results.&lt;/P&gt;

&lt;P&gt;What if we had 100 events from the query, and we wanted to display the values of &lt;CODE&gt;field_A&lt;/CODE&gt; that correspond to &lt;CODE&gt;N&lt;/CODE&gt; number of events that have another field &lt;CODE&gt;field_B&lt;/CODE&gt; = &lt;CODE&gt;some_field_value&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;The documentation doesn't seem to discuss anything more complex than pulling out single values, and it's making it difficult to build an email alert that provides charts of diagnostic information.&lt;/P&gt;

&lt;P&gt;Any help or useful resources to look at would be appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 14:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-you-properly-format-Splunk-email-alerts/m-p/450330#M7919</guid>
      <dc:creator>samsam48</dc:creator>
      <dc:date>2018-09-06T14:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly format Splunk email alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-you-properly-format-Splunk-email-alerts/m-p/450331#M7920</link>
      <description>&lt;P&gt;Hi @samsam48,&lt;/P&gt;

&lt;P&gt;By &lt;CODE&gt;$result.fieldName$&lt;/CODE&gt; you are referring to the message field. If you want to put the entire result in the email content, you can use the &lt;CODE&gt;Include&lt;/CODE&gt; option  - the 7th option mentioned in the following documentation &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Emailnotification#Define_an_email_notification_for_an_alert_or_scheduled_report"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Emailnotification#Define_an_email_notification_for_an_alert_or_scheduled_report&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also you could opt to just add the  link to the results or add as a PDF/csv attachments.&lt;/P&gt;

&lt;P&gt;Hope that helps for your requirement&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 14:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-you-properly-format-Splunk-email-alerts/m-p/450331#M7920</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-09-06T14:36:42Z</dc:date>
    </item>
  </channel>
</rss>

