Alerting

How do I list fields vertically in an email alert?

MonkeyK
Builder

One problem that I have with alerting from Splunk is that when I alert by email, total width of the table can exceed what the recipient can handle lookin at.  I'd like to start transposing my result table to address this.

 

That is, I'd like to go from sending alerted results like this

timefield1field2field 3
5/31/2022value1value2really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

To something more like this:

Time: 5/31/2022

field1: value1

field2: values2

field3: really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

 

I know that I could create a field name called "alert fields" and manually create the fields, but is there a simple way to do this in Splunk

Labels (1)
0 Karma
1 Solution

DanielPriceUK
Path Finder

DanielPriceUK
Path Finder

| transpose

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...