I am using ITSI's KPI-based search for text log monitoring. If the text logs match the search criteria, the flow is to send an alert via email. I would like to quote the contents of the text logs that matched the detection criteria in the body of the email. Is it possible to implement such requirements with Splunk ITSI? If so, I would like to know the detailed content of the implementation. If not, I would like to know the reason why.
Hi @shoyo ... please check the sendemail command..
https://docs.splunk.com/Documentation/Splunk/9.1.1/SearchReference/Sendemail#Examples