Alerting

How to hidden a certain fields value in an Inline table in email alert?

phamxuantung
Path Finder

Hello,

My alert produces a table like this:

 

Time   |ID | FILE_NAME |STATUS
_time1 |3  |file1.csv  |SUCCESS
_time2 |5  |file2.csv  |DATA_ERROR

 

 

I want to send an Inline table that only contains STATUS=DATA_ERROR. But in the body of the email, I still want to use the token $result.Time$ and $result.FILE_NAME$ from the STATUS=SUCCESS.
Email body example:

1. File name success detail:

File name: file1.csv
Effective time: _time1

2. Data error detail:

ID |FILE_NAME|STATUS

5  |file2.scv        |DATA_ERROR

So it's basically, hide the STATUS=SUCCESS row- but still use its values in the token email.

Thank you in advance

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...