Splunk Search

How to pass the search results to an email body by using sendresults

lucas4394
Path Finder

I am using "sendresults" command and pass the search results to an email body template; however, the search results didn't show up from the body.  Unfortunately, the Splunk sendresults page doesn't have an example for passing the result to the email body.  I wonder if it is possible to pass search results to the email body.  Does anyone know?  

This is the sample code I used.

 

 

| makeresults
| eval score=90, email_to="john.doe@xyz.com", name="john"
| append [|makeresults | eval score=76, email_to="jane.doe@abc.com",name="jane"]
| fields - _time
| sendresults showresults=f subject="Your Score" body="Hi $result.name$", your score is $result.score$."

 

 

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...