<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending entity names in the email triggered from Correlation Searches. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476212#M133758</link>
    <description>&lt;P&gt;ITSI saved correlation searches as alert. Check with token: $result.fieldname$ in the subject.&lt;/P&gt;

&lt;P&gt;From SPlunk documentation:&lt;BR /&gt;
&lt;STRONG&gt;$result.fieldname$&lt;/STRONG&gt;: First value for the specified field name from the first search result row. Verify that the search generates the field being accessed.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2020 06:12:32 GMT</pubDate>
    <dc:creator>manjunathmeti</dc:creator>
    <dc:date>2020-02-19T06:12:32Z</dc:date>
    <item>
      <title>Sending entity names in the email triggered from Correlation Searches.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476211#M133757</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have a KPI with split by entity say "Ent1".&lt;BR /&gt;
I have made a correlation search using this KPI and in the triggered email, i want to send this entity in the subject line.&lt;BR /&gt;
Can anybody help me in this regard.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 05:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476211#M133757</guid>
      <dc:creator>veerendra_modi</dc:creator>
      <dc:date>2020-02-19T05:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sending entity names in the email triggered from Correlation Searches.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476212#M133758</link>
      <description>&lt;P&gt;ITSI saved correlation searches as alert. Check with token: $result.fieldname$ in the subject.&lt;/P&gt;

&lt;P&gt;From SPlunk documentation:&lt;BR /&gt;
&lt;STRONG&gt;$result.fieldname$&lt;/STRONG&gt;: First value for the specified field name from the first search result row. Verify that the search generates the field being accessed.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 06:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476212#M133758</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-19T06:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sending entity names in the email triggered from Correlation Searches.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476213#M133759</link>
      <description>&lt;P&gt;actually my entity is not coming in the generated search&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 09:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sending-entity-names-in-the-email-triggered-from-Correlation/m-p/476213#M133759</guid>
      <dc:creator>veerendra_modi</dc:creator>
      <dc:date>2020-05-21T09:17:57Z</dc:date>
    </item>
  </channel>
</rss>

