Splunk Search

Using map to sendemail (email body is empty)

Tim00
Explorer

Would like to automatically send an email to all email addresses which are the output of a search. My problem is that Splunk is indeed sending an email to all email addresses, like it should, but the email body is empty in all cases. 

This is the query which I use to send the email (the searchquery is above these line's, it's output is user_name, fullname and email):

|table user_name fullname email 
|map maxsearches=5000 search=" stats count
|eval email=\"$email$\"
|eval fullname=\"$fullname$\"
|table fullname email 
|sendemail to=$result.email$  subject="Subject" message=\"Dear colleague, XXXXXX Kind regards, Tim\" sendresults=true inline=true"

The query was created by a colleague of mine, who I can't ask for help anymore since he moved to a different company. Not sure what's wrong with this query. I tried to search the Splunk community and net, but was not able to come up with a solution by myself.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...