Sending email alert when the error count > 0 results; but how can include table data/values in the email alert?
( table _time, ERROR_CD, HAWB, UREF, LRN, MRN, ER1_ER9_Details )
Query:
index=gbs_its_openshift_exp-ics2 openshift_container_name="regulatory-engine" "ER1/ER9 errors"
| rex field=_raw "uref:(?<UREF>\w+)"
| rex field=_raw "hawb:(?<HAWB>\w+)"
| rex field=_raw "lrn:(?<LRN>\w+)"
| rex field=_raw "mrn:(?<MRN>\w+)"
| rex field=_raw "rrr:(?<RRR>\w+)"
| rex field=_raw "ER1\/ER9\serrors:(?<ER1_ER9_Details>.+)"
| rex field=_raw "Err-\[(?<ERROR_CD>\w*)\]"
| table _time, ERROR_CD, HAWB, UREF, LRN, MRN, ER1_ER9_Details
| stats count
| search count > 0
This is working!!
| stats count as ERROR_CNT by ERROR_CD, UREF, HAWB, LRN, MRN, ER1_ER9_Details | where ERROR_CNT>0