Would like to automatically send an email to all email addresses which are the output of a search. My problem is that Splunk is indeed sending an email to all email addresses, like it should, but the email body is empty in all cases.
This is the query which I use to send the email (the searchquery is above these line's, it's output is user_name, fullname and email):
|table user_name fullname email
|map maxsearches=5000 search=" stats count
|eval email=\"$email$\"
|eval fullname=\"$fullname$\"
|table fullname email
|sendemail to=$result.email$ subject="Subject" message=\"Dear colleague, XXXXXX Kind regards, Tim\" sendresults=true inline=true"
The query was created by a colleague of mine, who I can't ask for help anymore since he moved to a different company. Not sure what's wrong with this query. I tried to search the Splunk community and net, but was not able to come up with a solution by myself.