Splunk Search

How to include only certain fields in an email sent from an alert

riotto
Path Finder

I have an alert that looks for a pattern in an event that is an xml: ie.

":2017-03-01 06:02:16,194 INFO 7010 System Error 7025 Failed Request Build null null"

I want to send the email that includes only the TransactionStatusMessageDetail field, but I get the _raw sent
(Failed Request Build) is the field
Can this be done? Splunk Enterprise version is 6.1

0 Karma
1 Solution

woodcock
Esteemed Legend

Just add | table TransactionStatusMessageDetail as the last part of your search.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just add | table TransactionStatusMessageDetail as the last part of your search.

0 Karma

riotto
Path Finder

Works like a champ!...thanks

0 Karma

woodcock
Esteemed Legend

Be sure to click Accept to close the question.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...