I was hoping to do a single search, and from that sent multiple emails based on field (all to same place set up in alert)
i.e. results
user,Group,Owner
user1,Domain Admins,Joe
user1,Sharepoint Users,Paul
user2,Internet Users,Paul
user3,Excange Users,Dave
I want 3 emails sent from that, broken down by owner
email1
user,Group,Owner
user1,Domain Admins,Joe
email2
user,Group,Owner
user1,Sharepoint Users,Paul
user2,Internet Users,Paul
email3
user,Group,Owner
user3,Excange Users,Dave
The result will basically come from a search similar to below
(EventCode=636 OR EventCode=660 OR EventCode=632) | lookup PermissionGroups.csv Target_Account_Name OUTPUT CSV_Priority,CSV_Owner | search CSV_Priority="*" | rename Target_Account_Name AS Group | rename Member_ID as "Account Added" | rename Caller_User_Name AS "Actioning Account" | rename CSV_Owner as Owner |table _time,"Account Added",Group,"Actioning Account",Owner
... View more