Reporting

Remove query from Emails

Hazel
Communicator

Hello,

Is there a way to remove the splunk query from the email that is sent out? A lot of our emails go out to users, so we just want them to see the table of results and don't want them to get confused with the query that we ran.

I see an option to include the results. Is there no option to exclude the splunk query?

Thanks Hazel

Tags (1)

DerekB
Splunk Employee
Splunk Employee

Starting in Splunk 6.1, this ability is built into the product. Edit your search and look under the "Click to edit email action" link in the "Alert Actions" section. It's a simple check box you can uncheck. It's in the picture in step 4.

http://docs.splunk.com/Documentation/Splunk/6.1.1/Alert/Setupalertactions

jcrane
Explorer

I have read the other posts for this as well as this one and the answers are not good ones. This should be an option in the UI.

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

Unfortunately there's no well supported way of doing this, but it's a good enhancement request to forward on to Customer Support.

If you are feeling daring, you can modify $SPLUNK_HOME/etc/apps/search/bin/sendemail.py which renders emails. Note that any modifications will be overwritten on upgrade.

southeringtonp
Motivator

If you do modify the script, DON'T modify it in-place. Instead, make a copy and override the sendemail command in the search app. There has been some discussion along these lines in some older threads, including this one -- http://answers.splunk.com/questions/6423/how-to-change-default-alert-smtp-port

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...