Alerting

How can I keep order of fields in plain format of an alert email?

Masa
Splunk Employee
Splunk Employee

In email alert as plain text format, the order of fields of a search result is not kept. It is rearranged to keep shorter field first.

For example,


==> SavedSearch Result
TIME COUNT

2012/02/10 09:05:00 163

2012/02/10 09:06:00 1810

2012/02/10 09:07:00 1115

2012/02/10 09:08:00 1240

2012/02/10 09:09:00 672

==> Same search result sent in Email alert (Plain Text)
COUNT TIME

163 2012/02/10 09:05:00

1810 2012/02/10 09:06:00

1115 2012/02/10 09:07:00

1240 2012/02/10 09:08:00

672 2012/02/10 09:09:00


How can I keep the fields order of the search result in plain text email alert?

Tags (2)
0 Karma

woodcock
Esteemed Legend

It is reordering them based on alphabetical order. To keep the order, add this to the bottom:

| rename TIME AS " TIME"
0 Karma

wryanthomas
Contributor

That was not my experience. It was sorting them as the documentation indicates -- by an internal assessment of the length (or width) of fields. You can now set that setting -- width_sort_columns -- to "false" in the GUI.

0 Karma

woodcock
Esteemed Legend

Interesting.

0 Karma

Masa
Splunk Employee
Splunk Employee

In 4.3, we added an attribute for [email] stanza in alert_actions.conf

- alert_actions.conf
[email]
width_sort_columns = 0

This will keep the order of search result in plain text email.

Unfortunately you cannot select this option through WebGUI at this time. So, you need to edit alert_actions.conf manually.

wryanthomas
Contributor

It is now available in the gui, under "advanced edit" for the alert.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...