Alerting

How do I list fields vertically in an email alert?

MonkeyK
Builder

One problem that I have with alerting from Splunk is that when I alert by email, total width of the table can exceed what the recipient can handle lookin at.  I'd like to start transposing my result table to address this.

 

That is, I'd like to go from sending alerted results like this

timefield1field2field 3
5/31/2022value1value2really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

To something more like this:

Time: 5/31/2022

field1: value1

field2: values2

field3: really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

 

I know that I could create a field name called "alert fields" and manually create the fields, but is there a simple way to do this in Splunk

Labels (1)
0 Karma
1 Solution

DanielPriceUK
Path Finder

DanielPriceUK
Path Finder

| transpose

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...