How to format alerts email message in alert search, and split the message over multiple lines

Path Finder


I use the following in the Alert Search to get the Email Message (body) in the Splunk Results output:

| eval Alert_Message= "Text A, Text B, Text C"
| table Alert_Message ...

It shows the Message in the Splunk Results output in 'One single line' > Text A, Text B, Text C


Is it possible to get the Splunk Results output, e.g. in 3 Lines?
Text A
Text B
Text C

0 Karma

Path Finder

I actually solved it myself, by adding a star after each line, and using | makemv delim="*" Alert_Message

0 Karma


You can also use the mvexpand command here: You should post/accept an answer or close the question to mark it as resolved!

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...