Splunk Enterprise Security

Splunk ES APP Correlation Search Email Output Action

skathpal
Explorer

Hello Everyone,

I need to setup the email output action for ES APP correlation Searches , I have found that we cant write the message body in Correlation Searches .

Kindly help , I need to write message body of each correlation searches so that we can see more useful information , Once we get the email of any alert .

Thanks in Advance

0 Karma

skathpal
Explorer

Help Required ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...