Splunk Search

How to include only certain fields in an email sent from an alert

riotto
Path Finder

I have an alert that looks for a pattern in an event that is an xml: ie.

":2017-03-01 06:02:16,194 INFO 7010 System Error 7025 Failed Request Build null null"

I want to send the email that includes only the TransactionStatusMessageDetail field, but I get the _raw sent
(Failed Request Build) is the field
Can this be done? Splunk Enterprise version is 6.1

0 Karma
1 Solution

woodcock
Esteemed Legend

Just add | table TransactionStatusMessageDetail as the last part of your search.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just add | table TransactionStatusMessageDetail as the last part of your search.

0 Karma

riotto
Path Finder

Works like a champ!...thanks

0 Karma

woodcock
Esteemed Legend

Be sure to click Accept to close the question.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...