All Apps and Add-ons

Any plans on adding ability to dynamically update the subject/body based on results for sendresults command?

cramasta
Builder

I really like the sendresults command as it can send multiple rows together in a single email that all have the same email address (and not show the email address in the results table!). It takes the "Spunk Alert Mode: Once Per Result" to another level.

One thing that would be nice to see if we could also customize the subject/body of the email dynamically based on the results that are being sent. For example if i have index=foo | stats count by host, where each host sends to a different email address, I can customize the subject line to include the value of the host field, kinda like how we do the email addresses with email_to field.

0 Karma

mockd
Path Finder

Hi!

Thank you for your interest in the sendresults command. Currently that functionality is not available, but we are looking to release a new version of the command and this would make a great feature to add in. Should be easily doable.

We appreciate the feedback!

D.

0 Karma

jkat54
SplunkTrust
SplunkTrust

in dashboards we pass variables around called tokens. I'm curious if you could pass a token to sendemail command.

$fieldname$ might work...

0 Karma

jkat54
SplunkTrust
SplunkTrust
0 Karma

cramasta
Builder

Hey thanks for the reply. Unfortunately that doesn't seem to work but you got the right idea as for what Im trying to do.

This if for the sendresults command from this app.
https://splunkbase.splunk.com/app/1794/

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...