Reporting

I want to get emails with out the whole body.

blainsupplymis
New Member

I been trying to find the best way to remove some of the extra stuff inside of the email body.
the current body looks like below
Saved search results.

Name: 'test-alert'
Query Terms: 'source=\"udp:514\" sourcetype=\"cisco_asa\"'
Link to results: https://blnmonitor:8000/app/search/@go?sid=scheduler__admin__search_dGVzdC1hbGVydA_at_1344613200_bea...
Alert was triggered because of: 'Saved Search [test-alert]: number of events(141)'

I want it to look something like this
On 2012-08-09 at approximately 17:19:23 BLNROUTER1 showed Chippewa Falls' T1 went up
or
Chippewa Fall's T1 went up

Tags (3)
0 Karma

blainsupplymis
New Member

That one doesn't work. I need to make changes to the alert_actions.conf, but I don't have much experience with pyton. I know in what area to make the changes, but I don't know how to write my own.
here is where I need to make the changes
command = $action.email.preprocess_results{default=""}$ | sendemail

"server=$action.email.mailserver{default=localhost}$" "use_ssl=$action.email.use_ssl{default=false}$"

"use_tls=$action.email.use_tls{default=false}$" "to=$action.email.to$" "cc=$action.email.cc$"

"bcc=$action.email.bcc$" "from=$action.email.from{default=splunk@localhost}$"

"subject=$action.email.subject{recurse=yes}$" "format=$action.email.format{def"sssummary=Saved Search [$name$]: $counttype$($results.count$)" "sslink=$results.url$" "ssquery=$search$" "ssname=$name$" "inline=$action.email.inline{default=False}$" "sendresults=$action.email.sendresults{default=False}$" "sendpdf=$action.email.sendpdf{default=False}$" "pdfview=$action.email.pdfview$" "searchid=$search_id$" "width_sort_columns=$action.email.width_sort_columns$" "graceful=$graceful{default=True}$" ault=csv}$"

maxinputs="$action.email.maxresults{default=10000}$" maxtime="$action.email.maxtime{default=5m}$"

0 Karma

yannK
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...