Alerting

Why is email alert not showing after creating a new field?

Shraddha
New Member

Hi,

I have extracted a new filed "proc_name" from source and added it to table command of existing query and i am generating an email alert which is not showing new filed "proc_name" value in email.

 

host=XXX index=YYY sourcetype=app_logs rc time_taken="*"
| search RC>=8
| table client_ip, proc_name, proc_id, RC, Message

 

client_ip

proc_name

proc_id

RC

Message

MsgIDLCPS0.   5030 7 Process 'UPROC' #50930 -   RC=7MsgIDLCPS0.
Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How have you extracted the proc_name field, i.e. what configuration have you used and where is it deployed?

0 Karma

Shraddha
New Member

I have extracted the field using filed extractor and named it "proc_name" and directly used it in table command. Tried to populate it in email using $result.proc_name$

0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...