Alerting

Why is email alert not showing after creating a new field?

Shraddha
New Member

Hi,

I have extracted a new filed "proc_name" from source and added it to table command of existing query and i am generating an email alert which is not showing new filed "proc_name" value in email.

 

host=XXX index=YYY sourcetype=app_logs rc time_taken="*"
| search RC>=8
| table client_ip, proc_name, proc_id, RC, Message

 

client_ip

proc_name

proc_id

RC

Message

MsgIDLCPS0.   5030 7 Process 'UPROC' #50930 -   RC=7MsgIDLCPS0.
Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How have you extracted the proc_name field, i.e. what configuration have you used and where is it deployed?

0 Karma

Shraddha
New Member

I have extracted the field using filed extractor and named it "proc_name" and directly used it in table command. Tried to populate it in email using $result.proc_name$

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...