Reporting

I want to get emails with out the whole body.

blainsupplymis
New Member

I been trying to find the best way to remove some of the extra stuff inside of the email body.
the current body looks like below
Saved search results.

Name: 'test-alert'
Query Terms: 'source=\"udp:514\" sourcetype=\"cisco_asa\"'
Link to results: https://blnmonitor:8000/app/search/@go?sid=scheduler__admin__search_dGVzdC1hbGVydA_at_1344613200_bea...
Alert was triggered because of: 'Saved Search [test-alert]: number of events(141)'

I want it to look something like this
On 2012-08-09 at approximately 17:19:23 BLNROUTER1 showed Chippewa Falls' T1 went up
or
Chippewa Fall's T1 went up

Tags (3)
0 Karma

blainsupplymis
New Member

That one doesn't work. I need to make changes to the alert_actions.conf, but I don't have much experience with pyton. I know in what area to make the changes, but I don't know how to write my own.
here is where I need to make the changes
command = $action.email.preprocess_results{default=""}$ | sendemail

"server=$action.email.mailserver{default=localhost}$" "use_ssl=$action.email.use_ssl{default=false}$"

"use_tls=$action.email.use_tls{default=false}$" "to=$action.email.to$" "cc=$action.email.cc$"

"bcc=$action.email.bcc$" "from=$action.email.from{default=splunk@localhost}$"

"subject=$action.email.subject{recurse=yes}$" "format=$action.email.format{def"sssummary=Saved Search [$name$]: $counttype$($results.count$)" "sslink=$results.url$" "ssquery=$search$" "ssname=$name$" "inline=$action.email.inline{default=False}$" "sendresults=$action.email.sendresults{default=False}$" "sendpdf=$action.email.sendpdf{default=False}$" "pdfview=$action.email.pdfview$" "searchid=$search_id$" "width_sort_columns=$action.email.width_sort_columns$" "graceful=$graceful{default=True}$" ault=csv}$"

maxinputs="$action.email.maxresults{default=10000}$" maxtime="$action.email.maxtime{default=5m}$"

0 Karma

yannK
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...