Alerting

How to configure alert to send only one email containing all field values rather than an email per field value?

packet_hunter
Contributor

So I have an alert that fires 5 emails, one email per value.

For example, I have an alert based on a report that provides 5 field values. Currently I receive a 5 emails, one for each field. I would like just one email containing all the fields and values. The following are the fields.

Alert Occurred
Alert name
Appliance
MD5
Attachment

I have selected (in the alert):
Number of Results is greater than 0
Trigger for each result (I think this is the problem)
Send email
include Inline Table, attach PDF

The PDF contains all the fields/values I would like.

Does anyone know how to reconfigure my alert to just one email?

Thank you

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

View solution in original post

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

packet_hunter
Contributor

that works!!! Thank you - please convert to an answer.

0 Karma

somesoni2
Revered Legend

here you go.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...