Alerting

How to merge output of two different Email Alerts

AKG1_old1
Builder

Hello,

We have two different email alerts both have different search queries. Our requirement is to combine output of both alerts in single email. we can't combine search queries in single as these are different queries.

For example:
1st alert output = list of data attached as csv in email.
2nd alert output = dashboard link + Inline table

alt text

Even these two alerts produce two different table and requirement is to show these tables one after another in same email.

Thanks

0 Karma

DavidHourani
Super Champion

Hi @agoyal,

That is currently not possible as a configuration for an email alert action in alert_actions.conf. The list of possible options can be found here :
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Alertactionsconf#.5Bemail.5D

You do however have a couple of options :
1- Use append to include both results in the same search and send those results by email. This won't however give you the exact format you need and the table won't look as neat as what you're showing in your snapshots.
2- Build a custom alert action for sending emails that allows you to specify which fields you want to include in the body and which fields you want to have in the attachment. This would be a great upgrade the to existing email alert action that is very limited as you've seen. In case you opt for that option you can follow this doc for help on how to build the alert action :
https://docs.splunk.com/Documentation/Splunk/7.2.6/AdvancedDev/ModAlertsIntro

Hope this helps.

Cheers,
David

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@agoyal - I'm sorry to say but that is not possible with current Splunk alerting mechanism.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...