Alerting

how to add description to alert e-mail

0range
Communicator

How to send e-mail alerts from Splunk with text description of the event?

Tags (2)
0 Karma

sloshburch
Ultra Champion

Check out my answer in http://answers.splunk.com/answers/41129/use-of-the-search-description-field-in-an-alert-email - I think it might be what you're looking for.

jtrucks
Splunk Employee
Splunk Employee

You will have to have the results of the search be descriptive in some way and have the results sent with the email (inline is a good idea here).

Alternatively, you can have a script triggered and then you can use the script to send the email, which will allow you to produce whatever output you want, including data from the results of the search itself.

--
Jesse Trucks
Minister of Magic
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...