<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Send same email alert to different email ids based on a condition in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/525729#M9865</link>
    <description>&lt;P&gt;hello,&lt;BR /&gt;&lt;BR /&gt;I have a saved search that triggers an alert in the form of an email.&lt;BR /&gt;I want that alert to be sent to different email id's based on a condition.&lt;BR /&gt;&lt;BR /&gt;For example, I have 7 applications values in the search result and each application has an application owner.&lt;BR /&gt;When the threshold value is reached for SLA&amp;nbsp; suppose, for a given application, only that application owner must be sent email to.&lt;BR /&gt;&lt;BR /&gt;Looking for inputs.&lt;BR /&gt;TIA.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 10:13:05 GMT</pubDate>
    <dc:creator>architkhanna</dc:creator>
    <dc:date>2020-10-21T10:13:05Z</dc:date>
    <item>
      <title>Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/525729#M9865</link>
      <description>&lt;P&gt;hello,&lt;BR /&gt;&lt;BR /&gt;I have a saved search that triggers an alert in the form of an email.&lt;BR /&gt;I want that alert to be sent to different email id's based on a condition.&lt;BR /&gt;&lt;BR /&gt;For example, I have 7 applications values in the search result and each application has an application owner.&lt;BR /&gt;When the threshold value is reached for SLA&amp;nbsp; suppose, for a given application, only that application owner must be sent email to.&lt;BR /&gt;&lt;BR /&gt;Looking for inputs.&lt;BR /&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 10:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/525729#M9865</guid>
      <dc:creator>architkhanna</dc:creator>
      <dc:date>2020-10-21T10:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/525756#M9868</link>
      <description>&lt;P&gt;hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;get the email id as a column in result lets say &lt;FONT color="#FF0000"&gt;email&lt;/FONT&gt;, and in the TO field of alert pass it as a token&amp;nbsp; &amp;nbsp;"&amp;nbsp; &lt;FONT color="#FF0000"&gt;$result.email$&lt;/FONT&gt;&amp;nbsp; "&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same can be achieved in search using sendemail in search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ayush1906_0-1603279766429.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11407i0970173172DA6684/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ayush1906_0-1603279766429.png" alt="ayush1906_0-1603279766429.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 11:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/525756#M9868</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2020-10-21T11:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527592#M9933</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/166490"&gt;@ayush1906&lt;/a&gt;&amp;nbsp;In this case, the email id values also will be present in the result email. But is there any way to send an email without a present in the result email?&lt;/P&gt;&lt;P&gt;The resulting email contains the below columns based on your suggestions.&lt;BR /&gt;Col A&amp;nbsp; &amp;nbsp;Col B&amp;nbsp; email&lt;/P&gt;&lt;P&gt;But, I am trying to get the result email like below&lt;BR /&gt;Col A Col B&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 19:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527592#M9933</guid>
      <dc:creator>impurush</dc:creator>
      <dc:date>2020-11-02T19:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527628#M9934</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44228"&gt;@impurush&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This seems to works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) For use in token in email header or body, create a version of the field you want with an underscore as a prefix (e.g., | eval _fieldA = fieldA). You will use this field in the token -- e.g., $result._fieldA$.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Use 'fields' command instead of 'table' command. (I thought I had to use 'table' command to order the fields as I wanted in the email output. But 'fields' seems to work for that purpose as well.) Be sure to include the underscore-prefixed version of the field you want (e.g., "_fieldA") to use as&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;token&lt;/EM&gt;&lt;SPAN&gt;. (I just put it at the end.) Because it is prefixed with underscore, it won't show up in email table output.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;credits:&amp;nbsp;wryanthomas&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;source:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Alerting/I-am-sending-a-table-in-mail-as-an-alert-but-I-want-to-hide-some/m-p/406467" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Alerting/I-am-sending-a-table-in-mail-as-an-alert-but-I-want-to-hide-some/m-p/406467&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 04:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527628#M9934</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2020-11-03T04:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527633#M9935</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/166490"&gt;@ayush1906&lt;/a&gt;&amp;nbsp;Awesome, thank you so much. I have been trying to overcome this scenario for the last three days. It is working perfectly and as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 04:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527633#M9935</guid>
      <dc:creator>impurush</dc:creator>
      <dc:date>2020-11-03T04:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Send same email alert to different email ids based on a condition</title>
      <link>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527636#M9936</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 05:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Send-same-email-alert-to-different-email-ids-based-on-a/m-p/527636#M9936</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2020-11-03T05:37:13Z</dc:date>
    </item>
  </channel>
</rss>

