<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send mail to user in search results in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524402#M9822</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Is there a way to use all results from the search, the $result.name$ only uses the first result of the field. My search has multiple results. I tried the token $results.name$ but did didn't seemed to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 13:02:45 GMT</pubDate>
    <dc:creator>Sasquatchatmars</dc:creator>
    <dc:date>2020-10-13T13:02:45Z</dc:date>
    <item>
      <title>Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524352#M9817</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have made a search that gives me every user who's password expires in less than 10 days. Is there a way to send an email daily to that user instead of the IT department? So I can fully automate this process and that the users themselves are notified in case of password expiring.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 09:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524352#M9817</guid>
      <dc:creator>Sasquatchatmars</dc:creator>
      <dc:date>2020-10-13T09:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524356#M9818</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226635"&gt;@Sasquatchatmars&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Create an alert based on your search (execute the search and click on "save as &amp;gt; alert" above the time picker).&lt;BR /&gt;&lt;BR /&gt;Here you would select the email notification action.&lt;BR /&gt;&lt;BR /&gt;You can get the details for the configuration here:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There is &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#Example_-_Send_email_to_different_recipients_based_on_search_results" target="_self"&gt;a paragraph&lt;/A&gt; that explains how you can send the alert to different users, based on the search results.&lt;BR /&gt;Do you have the email in the search results? If not, you could get it from a lookup that provides the email based on the username for example.&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 09:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524356#M9818</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-10-13T09:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524359#M9819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your comment. Do you know if it is possible to make an email template that is sent to those specified users? What a procedure that they need to follow for example?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 10:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524359#M9819</guid>
      <dc:creator>Sasquatchatmars</dc:creator>
      <dc:date>2020-10-13T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524363#M9820</link>
      <description>&lt;P&gt;Yes, it's all in the alert settings. You can give the subject and body of the email and use tokens to integrate values from the search results (for example the name of the user or the number of days until the pw expires).&lt;BR /&gt;&lt;BR /&gt;You reference fields from the search results with&amp;nbsp;&lt;SPAN&gt;$result.fieldname$, details in the link provided.&lt;BR /&gt;&lt;BR /&gt;Somethine like: "Hello $result.firstname$, your password will expire in $result.daysuntilexpiration$"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 10:09:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524363#M9820</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-10-13T10:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524364#M9821</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your help, this was exactly what I needed!&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 10:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524364#M9821</guid>
      <dc:creator>Sasquatchatmars</dc:creator>
      <dc:date>2020-10-13T10:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524402#M9822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Is there a way to use all results from the search, the $result.name$ only uses the first result of the field. My search has multiple results. I tried the token $results.name$ but did didn't seemed to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 13:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524402#M9822</guid>
      <dc:creator>Sasquatchatmars</dc:creator>
      <dc:date>2020-10-13T13:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524406#M9823</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226635"&gt;@Sasquatchatmars&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tokens are only assigned to the first row in the result set.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But try to set the trigger of the alert to &lt;EM&gt;"for each result&lt;/EM&gt;" instead of "&lt;EM&gt;once&lt;/EM&gt;".&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This should trigger an alert-&amp;gt;email for each of the search results, so an email is sent to every single user with expiring password.&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Ralph&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 13:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524406#M9823</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-10-13T13:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524418#M9824</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you this was the answer!&lt;/P&gt;&lt;P&gt;Sasquatchatmars&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 13:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/524418#M9824</guid>
      <dc:creator>Sasquatchatmars</dc:creator>
      <dc:date>2020-10-13T13:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Send mail to user in search results</title>
      <link>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/660479#M15422</link>
      <description>&lt;P&gt;Hi. Can you tell me the spl how to fetch the password expiry date and username from search results ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 05:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-mail-to-user-in-search-results/m-p/660479#M15422</guid>
      <dc:creator>swetham</dc:creator>
      <dc:date>2023-10-12T05:42:12Z</dc:date>
    </item>
  </channel>
</rss>

