<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eval shown in my email? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344888#M102182</link>
    <description>&lt;P&gt;valiquet- Thank you very much. I will give this search a test and update the same.&lt;/P&gt;</description>
    <pubDate>Sun, 11 Mar 2018 16:32:36 GMT</pubDate>
    <dc:creator>dave0970</dc:creator>
    <dc:date>2018-03-11T16:32:36Z</dc:date>
    <item>
      <title>eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344878#M102172</link>
      <description>&lt;P&gt;How do i get this search to send the following eval shown in my email? I am getting email now but no result found shown in the email body. Please help!!!&lt;/P&gt;

&lt;P&gt;host="irprapppvot*" PV-API-Key is required and was not provided or is invalid OR pvo.common.20002 | table _time, host | eval alert_contact="SysEng" | eval alert_description="pvo.common.20002 and PV-API-Key is required and was not provided or is invalid with more than 75 instances in a single minute. NOC to cycle the indicated host. If the issue is still happening, contact SysEng to investigate."&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:24:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344878#M102172</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2020-09-29T18:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344879#M102173</link>
      <description>&lt;P&gt;Does your search &lt;BR /&gt;
    host="irprapppvot*" PV-API-Key is required and was not provided or is invalid OR pvo.common.20002&lt;BR /&gt;
yields at least one result always?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 01:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344879#M102173</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2018-03-10T01:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344880#M102174</link>
      <description>&lt;P&gt;Hey dave0970,&lt;/P&gt;

&lt;P&gt;Looks like your eval is not a condition but a message to the end user and you can add it in description whereas for alert to trigger you need condition to be satisfied.&lt;BR /&gt;
Refer this doc below:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/AlertTriggerConditions"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/AlertTriggerConditions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Let me know if this helps!!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 01:39:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344880#M102174</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-03-10T01:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344881#M102175</link>
      <description>&lt;P&gt;This event search already happen. I just need to know what to put in the search so when the alert comes in email it will shown contact syseng and description what to do. Now it said result not found in the body. The time it happen was 3/7/18. &lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 03:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344881#M102175</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-10T03:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344882#M102176</link>
      <description>&lt;P&gt;Here is the e-mail body when the alert triggered. The eval instruction suppose to show on right below view result in splunk. but i don't see it. &lt;/P&gt;

&lt;P&gt;=========================&lt;BR /&gt;
Subject: Splunk Alert: PVO - API Error: PV API Key&lt;BR /&gt;
Importance: High&lt;/P&gt;

&lt;P&gt;There were 0 result(s).&lt;BR /&gt;
The alert took 66618.237 seconds to run.&lt;BR /&gt;
Alert:  PVO - API Error: PV API Key&lt;/P&gt;

&lt;P&gt;View results in Splunk &lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 17:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344882#M102176</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-10T17:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344883#M102177</link>
      <description>&lt;P&gt;Hi deepashri, here is the email body, it does not show the "eval" instruction to call syseng and description for the NOC. instead it just shown "No results found" . I believe i am missing something in my search strings. Any ideas will help a lot.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Subject: Splunk Alert: PVO - API Error: PV API Key&lt;BR /&gt;
Importance: High&lt;/P&gt;

&lt;P&gt;There were 0 result(s).&lt;BR /&gt;
The alert took 68633.408 seconds to run.&lt;BR /&gt;
Alert:  PVO - API Error: PV API Key&lt;/P&gt;

&lt;P&gt;View results in Splunk &lt;BR /&gt;
No results found.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 17:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344883#M102177</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-10T17:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344884#M102178</link>
      <description>&lt;P&gt;oppps sorry for the large font. Don't know why&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 18:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344884#M102178</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-10T18:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344885#M102179</link>
      <description>&lt;P&gt;The line of equal signs did it.  I changed them to a horizontal rule.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 20:02:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344885#M102179</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-03-10T20:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344886#M102180</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;

&lt;H1&gt;do you mind explain little bit more about your comment? or, perhaps edit my search?&lt;/H1&gt;

&lt;P&gt;host="irprapppvot*" PV-API-Key is required and was not provided or is invalid OR pvo.common.20002 | table _time, host | eval alert_contact="SysEng" | eval alert_description="pvo.common.20002 and PV-API-Key is required and was not provided or is invalid with more than 75 instances in a single minute. NOC to cycle the indicated host. If the issue is still happening, contact SysEng to investigate."&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344886#M102180</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2020-09-29T18:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344887#M102181</link>
      <description>&lt;P&gt;Configure your saved search to only send email if number of results is &amp;gt; 1&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval alert_description="pvo.common.20002 and PV-API-Key is required and was not provided or is invalid with more than 75 instances in a single minute. NOC to cycle the indicated host. If the issue is still happening, contact SysEng to investigate."
| append [ search host="irprapppvot*" PV-API-Key is required and was not provided or is invalid OR pvo.common.20002 
                   | table _time, host 
                   | eval alert_contact="SysEng" ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 11 Mar 2018 07:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344887#M102181</guid>
      <dc:creator>valiquet</dc:creator>
      <dc:date>2018-03-11T07:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344888#M102182</link>
      <description>&lt;P&gt;valiquet- Thank you very much. I will give this search a test and update the same.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 16:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344888#M102182</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-11T16:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: eval shown in my email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344889#M102183</link>
      <description>&lt;P&gt;Hi valiquet- Does this search required a match alert to happen for us to see the eval in the e-mail body? I set up is equal to 0 to test for now to see if this work. &lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 19:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-shown-in-my-email/m-p/344889#M102183</guid>
      <dc:creator>dave0970</dc:creator>
      <dc:date>2018-03-11T19:20:45Z</dc:date>
    </item>
  </channel>
</rss>

