How to include a full log-in Splunk alert message?
Make sure the field _raw is included in your search results. Then you could use $result._raw$ in an email alert for example.
https://docs.splunk.com/Documentation/Splunk/9.0.1/Alert/Emailnotification
Make sure the field _raw is included in your search results. Then you could use $result._raw$ in an email alert for example.
https://docs.splunk.com/Documentation/Splunk/9.0.1/Alert/Emailnotification
_fields are often hidden so you could try renaming _raw to raw
| rename _raw as raw