I have a resultant data like this:
Server Name Status Location Owner Email Id
A-Z1 Missing. Spain. AAA AAA@domain.com
A-Z2 Active Japan BBB BBB@domain.com
A-Z3 Missing Japan CCC. CCC@domain.com
I want to send email to individual owners with servers details, who's status is shown "MISSING"
This should get you started:
[ your current search ]
| search Status="Missing"
[| sendemail to="$EmailID$" subject="subject line" firstname.lastname@example.org message="Your server status is MISSING" ]
This is an adaptation from an old post: https://answers.splunk.com/answers/186045/how-can-i-use-a-combination-of-map-and-sendemail-t.html
I tried its not working
getting below warning
2020-04-26 16:52:22,953 +0400 WARNING sendemail:1505 - search results is empty, no email will be sent