<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email from Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576248#M200835</link>
    <description>&lt;P&gt;How is the email formatted? Are you inserting the results as an inline table?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Nov 2021 20:50:10 GMT</pubDate>
    <dc:creator>johnhuang</dc:creator>
    <dc:date>2021-11-24T20:50:10Z</dc:date>
    <item>
      <title>Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576245#M200833</link>
      <description>&lt;P&gt;I have splunk search -&amp;nbsp;index=cloud EventName: "Error Occurred" XChangeToSalesForce | rename message as "Message" _time as Time | table Time,Message&lt;/P&gt;&lt;P&gt;When i search on splunk search, i get the below response&lt;/P&gt;&lt;P&gt;1637759064&amp;nbsp;&amp;nbsp;Multiple Terms found for the same agency. Agency code:&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when the email is sent, i get nothing on the message field&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Message&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1637759064&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 20:49:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576245#M200833</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-24T20:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576248#M200835</link>
      <description>&lt;P&gt;How is the email formatted? Are you inserting the results as an inline table?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 20:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576248#M200835</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2021-11-24T20:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576254#M200840</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp; it is formatted as inline table, i tried inline raw as well&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 21:39:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576254#M200840</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-24T21:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576650#M200959</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp; any idea why it is skipping the Messages&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 19:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576650#M200959</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-29T19:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576931#M201067</link>
      <description>&lt;P&gt;Could you post a sample of the search result and also the email template config.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 18:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576931#M201067</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2021-12-01T18:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576938#M201069</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="viksvig_0-1638384842160.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17080iF4D01F76EA48C7CC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="viksvig_0-1638384842160.png" alt="viksvig_0-1638384842160.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is the search and I am getting the desired result here. But when Email is sent the Message field blanks out&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="viksvig_1-1638384948005.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17081iFBE9F640822D1B6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="viksvig_1-1638384948005.png" alt="viksvig_1-1638384948005.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 18:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576938#M201069</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-12-01T18:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576940#M201070</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="viksvig_0-1638385016488.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17082iB555C24B56F1CA9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="viksvig_0-1638385016488.png" alt="viksvig_0-1638385016488.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 18:57:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576940#M201070</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-12-01T18:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576942#M201071</link>
      <description>&lt;P&gt;That's strange and interesting. Lets rule out a few things.&lt;/P&gt;&lt;P&gt;1. Could you enable the options "Attach CSV" and "Attach PDF"? Run another test and see if the data is in the attachments.&lt;/P&gt;&lt;P&gt;2. Let's replace the data in Message with safe characters and see if that works.&lt;/P&gt;&lt;P&gt;| eval message="testing_"._time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 19:37:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576942#M201071</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2021-12-01T19:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Email from Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576954#M201073</link>
      <description>&lt;P&gt;Try to add the results in some log or lookup and check the output&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In case if it is empty check the data and if not try to send the alert to your mail id using&amp;nbsp; this&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;| makeresults | eval a = temp | table&amp;nbsp; a _time&lt;BR /&gt;&lt;BR /&gt;and use inline table in your alert&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 21:49:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Email-from-Splunk/m-p/576954#M201073</guid>
      <dc:creator>Siddharth</dc:creator>
      <dc:date>2021-12-01T21:49:49Z</dc:date>
    </item>
  </channel>
</rss>

