Alerting

How to configure alert to send only one email containing all field values rather than an email per field value?

packet_hunter
Contributor

So I have an alert that fires 5 emails, one email per value.

For example, I have an alert based on a report that provides 5 field values. Currently I receive a 5 emails, one for each field. I would like just one email containing all the fields and values. The following are the fields.

Alert Occurred
Alert name
Appliance
MD5
Attachment

I have selected (in the alert):
Number of Results is greater than 0
Trigger for each result (I think this is the problem)
Send email
include Inline Table, attach PDF

The PDF contains all the fields/values I would like.

Does anyone know how to reconfigure my alert to just one email?

Thank you

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

View solution in original post

somesoni2
Revered Legend

Did you select "Once" OR "For each result" under "Alert options" section (in UI, below Enable Actions section). YOu should be selecting "Once" for single email per alert execution.

packet_hunter
Contributor

that works!!! Thank you - please convert to an answer.

0 Karma

somesoni2
Revered Legend

here you go.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...