How to define mail alert format


As i know, splunk use the length of fields from shortest to longest by default, how to define the order in search command rather than modifing the i try field - _raw,index,source,sourcetype + interface,status, but seems not to work, and the extract fields i defined are not shown in mail-format. i use v4.1.4, thanks

In short, Splunk will reorder by field width on email even if you define them via 'table', or 'fields'. Refer to the above link to fix this issue.

By using the table we can set the order of the fields to display, if i got the question correctly!!

