Splunk Search

Help with sending multiple $result

LizAndy123
Path Finder

So I have successfully configured some reports and alerts that send the $result to Mattermost.

My question is how to deal with a search which returns maybe 5 results?

Example - Current search may return - Example Text : Hello World

How do I pass each individual  $result ?

So Search could return Hello World followed by Hello World2 followed by Hello World3 

If I put $result.text$ it prints Hello World but if I want to then show the second result or 3rd...is it possible through this>?

Labels (3)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @LizAndy123 

When configuring your alert, select it to run "For each result" under the Trigger setting as per the screenshot below:

livehybrid_0-1750696423295.png

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...