<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to select fields for email alert in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13029#M1128</link>
    <description>&lt;P&gt;This is exactly what I was looking for.  Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2010 21:30:41 GMT</pubDate>
    <dc:creator>Jaci</dc:creator>
    <dc:date>2010-05-07T21:30:41Z</dc:date>
    <item>
      <title>How to select fields for email alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13026#M1125</link>
      <description>&lt;P&gt;Is there any way to control the reported fields in an email alert? I have
configured splunk to add the search results inline, but I don't need all
the fields it is showing.  I only want the host and _raw fields to show up in the email. 
Can you point me in the direction where I can change this behavior?&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 22:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13026#M1125</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-05-06T22:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to select fields for email alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13027#M1126</link>
      <description>&lt;P&gt;You can control this by appending "| fields + host,_raw" to the search string&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 22:59:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13027#M1126</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2010-05-06T22:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to select fields for email alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13028#M1127</link>
      <description>&lt;P&gt;If Splunk is showing more fields then those two (_time) you can remove the fields you don't want by issuing the command | fields - _time after the | fields + host, _raw.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 13:53:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13028#M1127</guid>
      <dc:creator>CerielTjuh</dc:creator>
      <dc:date>2010-05-07T13:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to select fields for email alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13029#M1128</link>
      <description>&lt;P&gt;This is exactly what I was looking for.  Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 21:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13029#M1128</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-05-07T21:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to select fields for email alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13030#M1129</link>
      <description>&lt;P&gt;Thank you for the answer, this is helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 21:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-select-fields-for-email-alert/m-p/13030#M1129</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-05-07T21:31:14Z</dc:date>
    </item>
  </channel>
</rss>

