<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sendemail to a field value - without script? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175740#M50463</link>
    <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=reallyBadUsers | Table User, Manager, ManagerEmailAddr | sendemail [source=reallyBadUsers | Table ManagerEmailAddr | mvcombine delim="," ManagerEmailAddr | nomv ManagerEmailAddr  | rename ManagerEmailAddr as to]  sendresults=true priority=high subject="This guy is really bad"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 22 May 2014 16:51:41 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-05-22T16:51:41Z</dc:date>
    <item>
      <title>sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175739#M50462</link>
      <description>&lt;P&gt;Hi, I am trying to send search results to an email address using the sendemail command.&lt;/P&gt;

&lt;P&gt;If I "hardcode" the to field in my sendemail command, this works great.  However the goal is to send the email to a field value from the search itself..so..&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=reallyBadUsers | Table User, Manager, ManagerEmailAddr | sendemail to=$ManagerEmailAddr$ sendresults=true priority=high subject="This guy is really bad" server=x.x.x.x
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Obviously I've learned that $ManagerEmailAddr$ is not going to work.  &lt;/P&gt;

&lt;P&gt;How can I work around this? The "to" address will be dependent on the ManagerEmailAddr from the search.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 15:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175739#M50462</guid>
      <dc:creator>bcusick</dc:creator>
      <dc:date>2014-05-22T15:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175740#M50463</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=reallyBadUsers | Table User, Manager, ManagerEmailAddr | sendemail [source=reallyBadUsers | Table ManagerEmailAddr | mvcombine delim="," ManagerEmailAddr | nomv ManagerEmailAddr  | rename ManagerEmailAddr as to]  sendresults=true priority=high subject="This guy is really bad"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 22 May 2014 16:51:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175740#M50463</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-05-22T16:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175741#M50464</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I had same issue. The above query did not send email also. Please let me know if you are able to get the solution.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Pallavi&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 07:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175741#M50464</guid>
      <dc:creator>pallavibalasa</dc:creator>
      <dc:date>2016-08-26T07:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175742#M50465</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
you should go for the "sendresults Command": &lt;A href="https://splunkbase.splunk.com/app/1794/"&gt;https://splunkbase.splunk.com/app/1794&lt;/A&gt; (details here: &lt;A href="https://splunkbase.splunk.com/app/1794/#/details"&gt;app details&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;This app basically configures a custom command that allows you to:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Dynamically evaluate who to send&lt;BR /&gt;
results to, based upon the results of&lt;BR /&gt;
the search itself&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I used it in the past and it works charmingly..&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
regards&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 12:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175742#M50465</guid>
      <dc:creator>Nicolo_Figiani</dc:creator>
      <dc:date>2016-08-26T12:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175743#M50466</link>
      <description>&lt;P&gt;Hi somesoni2,&lt;/P&gt;

&lt;P&gt;From your above example, I got following query which is supposed send an email of the result, if result &amp;gt; 0 to predefined user email. The src_email needs to be dynamically set. But it is sending the email even though there is no result. Please advise how to update it to only sendemail when result &amp;gt; 0. Thanks&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
 earliest=-60m@m index=network comment="&lt;EM&gt;Comment&lt;/EM&gt;" &lt;BR /&gt;
| dedup local_start_time src_name src_number src_email src_site src_location dest_name dst_number &lt;BR /&gt;
| table local_start_time src_name src_number src_email src_site src_location dest_name dst_number &lt;BR /&gt;
| eval from=src_email | sendemail &lt;BR /&gt;
    [ search earliest=-60m@m index=network comment="&lt;EM&gt;Comment&lt;/EM&gt;" &lt;BR /&gt;
    | dedup local_start_time src_name src_number src_email src_site src_location dest_name dst_number &lt;BR /&gt;
    | table src_email &lt;BR /&gt;
    | rename src_email as from] to="&lt;A href="mailto:mike@company.org" target="_blank"&gt;mike@company.org&lt;/A&gt;" format=table subject="Comment" server=mail.company.org sendresults=true inline=true &lt;/PRE&gt;&lt;BR /&gt;
&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/175743#M50466</guid>
      <dc:creator>lim2</dc:creator>
      <dc:date>2020-09-30T03:05:53Z</dc:date>
    </item>
    <item>
      <title>sendemail to a field value - without script?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/542029#M153522</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I ran into the same problem and here is how I get it to work by referencing the Result tokens part in Splunk's documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;Base search&amp;gt; 
| table User, EmailAddress 
| sendemail to=$result.EmailAddress$ from="me@example.com" ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/EmailNotificationTokens" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Alert/EmailNotificationTokens&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 19:22:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sendemail-to-a-field-value-without-script/m-p/542029#M153522</guid>
      <dc:creator>splunkyfun12721</dc:creator>
      <dc:date>2021-03-02T19:22:17Z</dc:date>
    </item>
  </channel>
</rss>

