Splunk Search

Send Separate Alert Email notification based on email column and result returned

Poojitha
Communicator

Hi All,

I have a lookup that contains set of email ids and associated accounts.

Example : 

Account ID

OWNER_EMAIL

34234234

test1@gmail.com; test2@gmail.com

123234234

test3@gmail.com;test4@gmail.com


<logic>
| eval email_list = split(OWNER_EMAIL, ";")
| stats values(email_list) as email_list values(ENVIRONMENT) as ENVIRONMENT values(category) as EVENT_CATEGORY values(EVENT_TYPE) as EVENT_TYPE values(REGION) as Region values(AFFECTED_RESOURCE_ARNS) as AFFECTED_RESOURCE_ARNS.

I have configured $result.email_list$ in alert action - email.to setting. Email is getting sent successfully but all of the result together is sent to email recepient.

Result :

Account ID

 Email_list

Environment

Category

Type

Region

Arns

Description

34234234

test1@gmail.com; test2@gmail.com

Development

test_cat1

Event1

global

testarn1

testdescr1

123234234

test3@gmail.com;test4@gmail.com

Production

test_cat2

Event2

global

testarn2

testdescr2


When alert is triggered, separate email should go to test1@gmail.com; test2@gmail.com with both of them in to field  with email body containing only first row and another email should go to test3@gmail.com;test4@gmail.com with  both of them in to field with email body containing only second row. Please help how to achieve this.

Regards,
PNV

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Poojitha ,

when you create the alert, use the $row.OWNER_EMAIL$ token in the "Send to" field,

remembering to separate alerts results (one alert for each results) in the alert options.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...