Alerting

Why is email alert not showing after creating a new field?

Shraddha
New Member

Hi,

I have extracted a new filed "proc_name" from source and added it to table command of existing query and i am generating an email alert which is not showing new filed "proc_name" value in email.

 

host=XXX index=YYY sourcetype=app_logs rc time_taken="*"
| search RC>=8
| table client_ip, proc_name, proc_id, RC, Message

 

client_ip

proc_name

proc_id

RC

Message

MsgIDLCPS0.   5030 7 Process 'UPROC' #50930 -   RC=7MsgIDLCPS0.
Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How have you extracted the proc_name field, i.e. what configuration have you used and where is it deployed?

0 Karma

Shraddha
New Member

I have extracted the field using filed extractor and named it "proc_name" and directly used it in table command. Tried to populate it in email using $result.proc_name$

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...