Dashboards & Visualizations

email Alert with table values

4uramana4u
Explorer

 

Sending email alert when the error count > 0 results;  but how can include table data/values in the email alert? 

( table _time, ERROR_CD, HAWB, UREF, LRN, MRN, ER1_ER9_Details )

Query: 

index=gbs_its_openshift_exp-ics2 openshift_container_name="regulatory-engine" "ER1/ER9 errors"
| rex field=_raw "uref:(?<UREF>\w+)"
| rex field=_raw "hawb:(?<HAWB>\w+)"
| rex field=_raw "lrn:(?<LRN>\w+)"
| rex field=_raw "mrn:(?<MRN>\w+)"
| rex field=_raw "rrr:(?<RRR>\w+)"
| rex field=_raw "ER1\/ER9\serrors:(?<ER1_ER9_Details>.+)"
| rex field=_raw "Err-\[(?<ERROR_CD>\w*)\]"
| table _time, ERROR_CD, HAWB, UREF, LRN, MRN, ER1_ER9_Details
| stats count
| search count > 0

Tags (1)
0 Karma

4uramana4u
Explorer

This is working!!

| stats count as ERROR_CNT by ERROR_CD, UREF, HAWB, LRN, MRN, ER1_ER9_Details | where ERROR_CNT>0

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...