Alerting

truncate alert results

0range
Communicator

Hi all.
I trigger an alert based on a search and I want to see the number of result in the theme of e-mail, I also want to see some results in the body, but not all results, just 20 examples.
Is it possible?

0 Karma

MuS
Legend

Hi 0range,

Yes, this is possible if you do create your own custom alert script like written in the docs.

Update: another useful link on this topic is in the wiki.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...