<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk alert mail is in plain text in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406205#M6780</link>
    <description>&lt;P&gt;Thanks for the answer. I checked this and do not see any conent_type Settings at all.&lt;BR /&gt;
however, when I Change the alert Action in the Splunk-GUI  to 'Plain Text' THEN I see the following when running btool:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/TEST/local/savedsearches.conf                        action.email.content_type = plain&lt;/P&gt;

&lt;P&gt;As soon as I Switch alert type Setting  back to 'HTML &amp;amp; plain Text' in the gui the Content_type Setting disappers.&lt;BR /&gt;
Is html the Default?&lt;/P&gt;</description>
    <pubDate>Wed, 23 May 2018 06:46:04 GMT</pubDate>
    <dc:creator>c155969</dc:creator>
    <dc:date>2018-05-23T06:46:04Z</dc:date>
    <item>
      <title>Splunk alert mail is in plain text</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406203#M6778</link>
      <description>&lt;P&gt;I have configured an alert in Splunk Enterprise 6.6.3.&lt;BR /&gt;
The alert itself works and I get the Email.&lt;BR /&gt;
But the Email content is wrong it look like:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;From: &lt;A href="mailto:no.reply@test.com" target="_blank"&gt;no.reply@test.com&lt;/A&gt;&lt;BR /&gt;
Date: Mon, 21 May 2018 12:01:01 +0200&lt;BR /&gt;
X-Priority: 3&lt;BR /&gt;
X-Splunk-Name: My test error&lt;BR /&gt;
X-Splunk-Owner: splunkuser&lt;BR /&gt;
X-Splunk-App: TEST&lt;BR /&gt;
X-Splunk-SID: scheduler_&lt;EM&gt;splunkuser&lt;/EM&gt;&lt;EM&gt;TEST&lt;/EM&gt;_RMD5f5ddfff38b8f486c_at_1526896860_9502&lt;BR /&gt;
X-Splunk-ServerName: splunkserver&lt;BR /&gt;
X-Splunk-Version: 6.6.3&lt;BR /&gt;
X-Splunk-Build: e21ee54bc796&lt;BR /&gt;
X-CompuMailGateway: Version: 6.00.4.17261.x86_64 COMPUMAIL Date: 20180521100101Z&lt;BR /&gt;
Content-Type: multipart/mixed; boundary="===============1519125244710537315=="&lt;BR /&gt;
This is a multi-part message in MIME format.&lt;BR /&gt;
--===============1519125244710537315==&lt;BR /&gt;
Content-Type: multipart/alternative;&lt;BR /&gt;
 boundary="===============0576424335523694884=="&lt;BR /&gt;
MIME-Version: 1.0&lt;BR /&gt;
--===============0576424335523694884==&lt;BR /&gt;
MIME-Version: 1.0&lt;BR /&gt;
Content-Type: text/plain; charset="utf-8"&lt;BR /&gt;
Content-Transfer-Encoding: base64&lt;BR /&gt;
VGhlIGFsZXJ0IGNvbmRpdGlvbiBmb3IgJ015IHRlc3QgZXJyb3InIHdhcyB0cmlnZ2VyZWQgaW4gVEVTVCBlbnZpcm9ubWVudC4NCg0KYW4gcmVjZWl2ZXI6DQpPbi4u&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;What do I wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406203#M6778</guid>
      <dc:creator>c155969</dc:creator>
      <dc:date>2020-09-29T19:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert mail is in plain text</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406204#M6779</link>
      <description>&lt;P&gt;Check what's the &lt;CODE&gt;content_type&lt;/CODE&gt; set for your alert email. You can run btool command on the search head where that alert search exists and see.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$Splunk_home/bin/splunk btool savedsearches list "YourAlertSearchNameHere" --debug

content_type = [html|plain]
* Specify the content type of the email.
  * plain sends email as plain text
  * html sends email as a multipart email that include both text and html.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 22 May 2018 15:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406204#M6779</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-05-22T15:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk alert mail is in plain text</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406205#M6780</link>
      <description>&lt;P&gt;Thanks for the answer. I checked this and do not see any conent_type Settings at all.&lt;BR /&gt;
however, when I Change the alert Action in the Splunk-GUI  to 'Plain Text' THEN I see the following when running btool:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/TEST/local/savedsearches.conf                        action.email.content_type = plain&lt;/P&gt;

&lt;P&gt;As soon as I Switch alert type Setting  back to 'HTML &amp;amp; plain Text' in the gui the Content_type Setting disappers.&lt;BR /&gt;
Is html the Default?&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 06:46:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-alert-mail-is-in-plain-text/m-p/406205#M6780</guid>
      <dc:creator>c155969</dc:creator>
      <dc:date>2018-05-23T06:46:04Z</dc:date>
    </item>
  </channel>
</rss>

