<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I get the raw events (Results of the search) in an Alert Email? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134482#M36755</link>
    <description>&lt;P&gt;Yes : You can include Inline listing of results, as &lt;STRONG&gt;a table, raw events, or CSV file&lt;/STRONG&gt; whent configuring your email actions.&lt;BR /&gt;
For more informations, take a look here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2015 11:55:04 GMT</pubDate>
    <dc:creator>stephanefotso</dc:creator>
    <dc:date>2015-04-14T11:55:04Z</dc:date>
    <item>
      <title>Can I get the raw events (Results of the search) in an Alert Email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134481#M36754</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am looking for a way to get the events in the alert email rather than the statistics i.e. I want to see what "view result" link shows on click on splunk page directly into the email.&lt;/P&gt;

&lt;P&gt;Is this even possible?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;BR /&gt;
Vinod.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 09:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134481#M36754</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-04-14T09:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can I get the raw events (Results of the search) in an Alert Email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134482#M36755</link>
      <description>&lt;P&gt;Yes : You can include Inline listing of results, as &lt;STRONG&gt;a table, raw events, or CSV file&lt;/STRONG&gt; whent configuring your email actions.&lt;BR /&gt;
For more informations, take a look here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 11:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134482#M36755</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2015-04-14T11:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can I get the raw events (Results of the search) in an Alert Email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134483#M36756</link>
      <description>&lt;P&gt;Hi Stephanefotso,&lt;/P&gt;

&lt;P&gt;Thanks for the reply, But this not what I am asking for sorry. I know we can include all this, but what I want it to get the events like they come up when we do a search by typing the query (I hope it is making sense what I am asking) with all the stuff like source type host etc etc.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 11:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134483#M36756</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-04-14T11:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can I get the raw events (Results of the search) in an Alert Email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134484#M36757</link>
      <description>&lt;P&gt;&lt;STRONG&gt;you can get raw events&lt;/STRONG&gt;. Let suppose You create an alert that send an email when the word &lt;STRONG&gt;error&lt;/STRONG&gt; is find  for the last 1 hours and it would send an email when found. &lt;BR /&gt;
Here is the query with the &lt;STRONG&gt;_internal&lt;/STRONG&gt; index: &lt;CODE&gt;index=_internal "error"&lt;/CODE&gt; . A search like this will provide &lt;STRONG&gt;events&lt;/STRONG&gt;, that you can decide to get in your &lt;STRONG&gt;mail&lt;/STRONG&gt; the same way you get it in splunk web when simply type the query, by silply include &lt;STRONG&gt;raw events&lt;/STRONG&gt; when configuring your email action. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 12:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134484#M36757</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2015-04-14T12:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can I get the raw events (Results of the search) in an Alert Email?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134485#M36758</link>
      <description>&lt;P&gt;Gotcha! Sorry I got confused.&lt;BR /&gt;
Thank you so much for you answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 15:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-I-get-the-raw-events-Results-of-the-search-in-an-Alert-Email/m-p/134485#M36758</guid>
      <dc:creator>vinodmadaan</dc:creator>
      <dc:date>2015-04-14T15:03:10Z</dc:date>
    </item>
  </channel>
</rss>

