Splunk Search

Extracting field data from alert to be emailed

reaver3020
New Member

I have an alert configured to automatically send an email upon a user account locking. I'm looking for the email to only include four fields: a specific event code (EventCode=4740), message (Message=A user account was locked out.), Caller Computer Name, and a timestamp of when the event occurred. How do I go about accomplishing this?

Thank you in advance.

0 Karma

maciep
Champion

can you share your current search? I mean, it should just be a matter of tabling those fields...and possibly creating them first if needed.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...