Other Usage

Prepending String to All Email Subjects

fredclown
Builder

Does anyone have a creative solution or know if there is an obscure way in Splunk to prepend a certain string to the beginning of email subjects that are sent from Splunk? I'm looking for something that users could not override when they create an alert or report. I do know about the email footer option in the email setup screen to add a static footer that cannot be altered by users and we do employ that as well. I'm trying to do something like this with the email subject. Thanks.

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@fredclown - Email is just an alert action that comes default with Splunk. As you mentioned currently there is no option to prepend in the subject.

  • You could raise as improvement in Splunk at https://ideas.splunk.com/
  • Or you could have your own custom Splunk alert action for email with all the same options, but there of course you could specify whatever subject you want in your own Python code. But somehow you would have to disable Splunk's built in Email action, so people don't use that to bypass your rule.

 

I hope this helps!!! Kindly upvote if it does!!

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

it's just like @VatsalJagani said. 

What is the issue which you try to solve with this Fixed header part? Maybe there is another solution which you could use to achieve your objectives?

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...