Alerting

How to configure alert to send only one email containing all field values rather than an email per field value?

packet_hunter
Contributor

So I have an alert that fires 5 emails, one email per value.

For example, I have an alert based on a report that provides 5 field values. Currently I receive a 5 emails, one for each field. I would like just one email containing all the fields and values. The following are the fields.

Alert Occurred
Alert name
Appliance
MD5
Attachment

I have selected (in the alert):
Number of Results is greater than 0
Trigger for each result (I think this is the problem)
Send email
include Inline Table, attach PDF

The PDF contains all the fields/values I would like.

Does anyone know how to reconfigure my alert to just one email?

Thank you

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

View solution in original post

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

packet_hunter
Contributor

that works!!! Thank you - please convert to an answer.

0 Karma

somesoni2
Revered Legend

here you go.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...