Splunk Search

Is it possible to email alerts with only an attachment, so without "view results" and "alert" links?

rrovers
Path Finder

I know there is an option "advanced search" but I can't find an option there to exclude the links

Labels (1)
0 Karma
1 Solution

rrovers
Path Finder

It looks different in my screen (maybe different version) but found this in "advanced search":

 

action.email.include.results_link

action.email.include.view_link

 
changing this to "0" is the solution for me

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Edit the alert and in the "When triggered" section, under Send Email choose the desired elements to include in email.

richgalloway_0-1637775209869.png

 

---
If this reply helps you, an upvote would be appreciated.

rrovers
Path Finder

It looks different in my screen (maybe different version) but found this in "advanced search":

 

action.email.include.results_link

action.email.include.view_link

 
changing this to "0" is the solution for me

View solution in original post

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!