Alerting
Highlighted

How can I transpose a table in an email alert?

Path Finder

So I am trying to figure out if there's a way to transpose a table in an email alert. I tried using: " | transpose"

The problem was that Splunk ended up splitting each row into an email event causing at least 15 emails to be sent for 1 event. I did try to use tokens, but I would like to keep the bold header fonts in the email, in addition to the fact that I don't want to have to create tokens for each email alert as there are at least 15 fields.

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

SplunkTrust
SplunkTrust

Can you provide more details like your alert search, alert conditions, alert type (once per search OR once per result ) etc.

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

Path Finder

alert search: dvc_plug_success
which is:

index=epo source=epo prodaction=Block threattype="Device Plug" | eval ettime=strftime(time, %m/%d/%y %H:%M:%S") | table time, eventid, hostname, ipaddress, domain, username, bustype, devplugutc, threatvector, threattype, productaction, devclassname,devdesc,devname,devcompatibleid, devinstanceid, pcivendorid, pcideviceid, usbclass, usbvendorid, usbproductid, usbserial, fstype, fsstate, fsvolserial, fsvol_label

Alert settings are:
alert type: real-time

trigger alert when "Per Result"
Actions: Send Email
Message: default email alerts
To include: link to alert, link to results, Inline: Table, Attach PDF
Type: HTML&Plain Text

Let me know if you need anything else.

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

SplunkTrust
SplunkTrust

YOu've setup a real-time alert, for which the alert type/triggering condition is per result. So if you alert search is generating 10 records, it will send out 10 alerts. I would suggest converting this to scheduled alert (runs with fixed time range and at a frequency) which allows a "once per search" triggering. See this link for more details on those two types of alerts:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Alert/AlertTypesOverview

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

Path Finder

The problem isn't the records. The issue is that in the emails I want the table to be vertical and not horizontal. If I use the transpose in the search, an email is produced for each field in the table. So there would be an email for time, another for event_id, another for hostname, and so on.

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

New Member

try to use below example in your email alert content . And change the BOLD world to what you want to put

Date : $$result.time_detected$$
Machine name: $$result.src$$
Username: $$result.user$$
Path: $$result.file_path$$

0 Karma
Highlighted

Re: How can I transpose a table in an email alert?

Path Finder

Thank you. That is what I did for now. However, I was hoping to keep the table format. Hopefully, in the future Splunk allows more options and/or customization for emails.

0 Karma