Alerting

How should tokens be used to include values of a multi-row search result in my email alert's subject line?

bharadwaja30
Explorer

I want to trigger an email alert when disk usage of any of my servers exceeds 70%. For that, I have written a search query that lists down all the servers that exceeded 70% usage, in a tabular format. Fine. Now I want to include the values of this multi row search result in my mail's subject. How can I make use of tokens to include the values of multi-row search result in my mail's subject?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi bharadwaja30,
see https://docs.splunk.com/Documentation/Splunk/6.5.1/Alert/EmailNotificationTokens
every way, with $result.fieldname$ you can insert the first occurrence of your search.
You can also insert a link to the results (there is a check button)
beware to the number of results in your eMail, because if they are too many you could exceed the eMail dimensions limits.
Bye.
Giuseppe

0 Karma

bharadwaja30
Explorer

Hi cusello,

Thank you for responding to my question.

Yeah, $result.fieldname$ gives only the first occurrence of search. That is, the value in the first row of that particular fieldname column. My question is, how to send the values in the 2nd,3rd.. rows of the same column using tokens? Hope you got my question.

thomasneat
Engager

I can't find an answer to this either and it's been 3 years since this one was asked.

0 Karma

dailv1808
Path Finder

me too, Splunk not support maybe

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...