Alerting

How do I list fields vertically in an email alert?

MonkeyK
Builder

One problem that I have with alerting from Splunk is that when I alert by email, total width of the table can exceed what the recipient can handle lookin at.  I'd like to start transposing my result table to address this.

 

That is, I'd like to go from sending alerted results like this

timefield1field2field 3
5/31/2022value1value2really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

To something more like this:

Time: 5/31/2022

field1: value1

field2: values2

field3: really long value 3, so long that it creates a formatting problem. Oh noes! What will I do?

 

I know that I could create a field name called "alert fields" and manually create the fields, but is there a simple way to do this in Splunk

Labels (1)
0 Karma
1 Solution

DanielPriceUK
Path Finder

DanielPriceUK
Path Finder

| transpose

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...