I have an alert that has message content to be sent in an email:
e.g.
Message
Message info here returned about the alert
When the alert triggers the message info is returned followed by the alert.
How do i get the alert info to be returned and the message info (in the message box) to be displayed please?
So
alert 1 results
followed by message info
not:
message
followed by an alert
I think one of the only things you can do is to just add a token into your message body that adds more information about the alert (like $result.fieldname$
), but it wouldn't really be swapping them around.
http://docs.splunk.com/Documentation/Splunk/6.5.2/Alert/EmailNotificationTokens