Splunk Search

Sendmail command in query doest not popoulate the Dashboard

vikramyadav
Contributor

I am creating a dashboard with mail to button in it, in the query I have inserted the sendmail to command at the end. The observation is If I have the sendemail at the end then visual table does not populate below, at the same time if I remove it then the table gets populated. How to show the table results using sendmail command.

alt text

I am using the text field input as mail ID from user also query is simple with table command in it ..


.......| table host | sendemail to="$mail$" subject=failed_login server=smtp sendresults=true


somesoni2
Revered Legend

Give this a try

your current search before sendemail command
| appendpipe [| sendemail....portion..here...]
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...