<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to include only certain fields in an email sent from an alert in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332789#M175307</link>
    <description>&lt;P&gt;Be sure to click &lt;CODE&gt;Accept&lt;/CODE&gt; to close the question.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2017 19:53:38 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-03-01T19:53:38Z</dc:date>
    <item>
      <title>How to include only certain fields in an email sent from an alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332786#M175304</link>
      <description>&lt;P&gt;I have an alert that looks for a pattern in an event that is an xml:  ie.&lt;/P&gt;

&lt;P&gt;":2017-03-01 06:02:16,194 INFO  7010 System Error 7025 Failed Request Build null null"&lt;/P&gt;

&lt;P&gt;I want to send the email that includes only the TransactionStatusMessageDetail field, but I get the _raw sent&lt;BR /&gt;
(Failed Request Build) is the field&lt;BR /&gt;
Can this be done? Splunk Enterprise version is 6.1&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332786#M175304</guid>
      <dc:creator>riotto</dc:creator>
      <dc:date>2017-03-01T19:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to include only certain fields in an email sent from an alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332787#M175305</link>
      <description>&lt;P&gt;Just add &lt;CODE&gt;| table TransactionStatusMessageDetail&lt;/CODE&gt; as the last part of your search.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332787#M175305</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-01T19:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to include only certain fields in an email sent from an alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332788#M175306</link>
      <description>&lt;P&gt;Works like a champ!...thanks&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:30:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332788#M175306</guid>
      <dc:creator>riotto</dc:creator>
      <dc:date>2017-03-01T19:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to include only certain fields in an email sent from an alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332789#M175307</link>
      <description>&lt;P&gt;Be sure to click &lt;CODE&gt;Accept&lt;/CODE&gt; to close the question.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:53:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-only-certain-fields-in-an-email-sent-from-an/m-p/332789#M175307</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-01T19:53:38Z</dc:date>
    </item>
  </channel>
</rss>

