Splunk Search

Sendmail command in query doest not popoulate the Dashboard


I am creating a dashboard with mail to button in it, in the query I have inserted the sendmail to command at the end. The observation is If I have the sendemail at the end then visual table does not populate below, at the same time if I remove it then the table gets populated. How to show the table results using sendmail command.

alt text

I am using the text field input as mail ID from user also query is simple with table command in it ..

.......| table host | sendemail to="$mail$" subject=failed_login server=smtp sendresults=true

Give this a try

your current search before sendemail command
| appendpipe [| sendemail....portion..here...]
