How to define mail alert format


As i know, splunk use the length of fields from shortest to longest by default, how to define the order in search command rather than modifing the i try field - _raw,index,source,sourcetype + interface,status, but seems not to work, and the extract fields i defined are not shown in mail-format. i use v4.1.4, thanks

0 Karma

New Member

In short, Splunk will reorder by field width on email even if you define them via 'table', or 'fields'. Refer to the above link to fix this issue.

0 Karma


By using the table we can set the order of the fields to display, if i got the question correctly!!

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!