Reporting

How to include the current date and time in the email when using the sendemail command in a search?

rkanumula
Path Finder

hi,

i have to attach the current time in sendemail
Below is my search:

index=_internal| head 5|table source,sourcetype | sendemail to=abc@abc.com server=localhost subject="Report No 1 has been executed at"+""+now()  message="This is an example message" sendresults=true inline=true format=raw sendpdf=false

and also i have tried

index=_internal| head 5|table source,sourcetype | sendemail to=abc@abc.com server=localhost subject="Report No 1 has been executed at"+""+$_time$  message="This is an example message" sendresults=true inline=true format=raw sendpdf=false

but i am not getting the date in the message.

Getting Output:
Report No 1 has been executed at

Expected Output:
My Subject : Report No 1 has been executed at 27/05/2015 10.12.10 AM

Please suggest how to edit my search.

Thanks in Advance

Tags (4)
0 Karma

stephanefotso
Motivator

Hello!
Why don't you use the Email Actions dialog box to send your email? it will be simple, by using $job.earliestTime$ inthe subject field.
Thanks

SGF

manirao
Explorer

@ stephan

[November 05, 2018] [03:12:04] , this does not give AM or PM
So, either it should give AM/PM or give the value in 24 H format

Thanks in Advance

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...