We have a request from a user that he wants to add his own attachment (which describes what the error code is, defines it, sets the action to be taken, and who is responsible for the action) to the Splunk email notification every time the business unit (app team) receives the email from Splunk on a specific condition.
In Settings->System settings->Email settings, there is an "Email footer" text box. Perhaps you could use that to include a link to the attachment.
Thanks for your reply! I am looking for a way we can attach to specific scheduled search alert. it will affect global if we update the footer in email settings.
I think you'll have to submit an RFE for that.