Splunk Search

Can I get the raw events (Results of the search) in an Alert Email?

vinodmadaan
Path Finder

Hi,

I am looking for a way to get the events in the alert email rather than the statistics i.e. I want to see what "view result" link shows on click on splunk page directly into the email.

Is this even possible?

Thanks in advance.
Vinod.

Tags (4)
0 Karma
1 Solution

stephanefotso
Motivator

Yes : You can include Inline listing of results, as a table, raw events, or CSV file whent configuring your email actions.
For more informations, take a look here: http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions

SGF

View solution in original post

0 Karma

stephanefotso
Motivator

Yes : You can include Inline listing of results, as a table, raw events, or CSV file whent configuring your email actions.
For more informations, take a look here: http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions

SGF
0 Karma

vinodmadaan
Path Finder

Hi Stephanefotso,

Thanks for the reply, But this not what I am asking for sorry. I know we can include all this, but what I want it to get the events like they come up when we do a search by typing the query (I hope it is making sense what I am asking) with all the stuff like source type host etc etc.

0 Karma

stephanefotso
Motivator

you can get raw events. Let suppose You create an alert that send an email when the word error is find for the last 1 hours and it would send an email when found.
Here is the query with the _internal index: index=_internal "error" . A search like this will provide events, that you can decide to get in your mail the same way you get it in splunk web when simply type the query, by silply include raw events when configuring your email action.

SGF

vinodmadaan
Path Finder

Gotcha! Sorry I got confused.
Thank you so much for you answer 🙂

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...