Splunk® Enterprise

Search Reference

Download manual as PDF

Splunk version 4.x reached its End of Life on October 1, 2013. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

sendemail

Synopsis

Emails search results to specified email addresses.

Syntax

sendemail to=<email_list> [from=<email_list>] [cc=<email_list>] [bcc=<email_list>] [format=(html | raw | text | csv)] [inline= (bool)] [sendresults=(bool)] [sendpdf=(bool)] [priority= (highest | high | normal | low | lowest)][server=<string>] [width_sort_columns=(bool)] [graceful=(bool)]

Required arguments

to
Syntax: to=<email_list>
Description: List of email addresses to send search results to.

Optional arguments

bcc
Syntax: bcc=<email_list>
Description: Blind cc line; comma-separated and quoted list of valid email addresses.
cc
Syntax: cc=<email_list>
Description: Cc line; comma-separated quoted list of valid email addresses.
format
Syntax: format= csv | html | raw | text
Description: Specifies how to format the email's contents.
Default: HTML
from
Syntax: from=<email_list>
Description: Email address from line.
Default: "splunk@<hostname>"
inline
Syntax: inline=bool
Description: Specifies whether to send the results in the message body or as an attachment.
Default: true
graceful
Syntax: graceful=bool
Description: If set to true, no error is thrown, if email sending fails and thus the search pipeline continues execution as if sendemail was not there.
Default: false
priority
Syntax: priority=highest | high | normal | low | lowest
Description: Set the priority of the email as it appears in the email client. Lowest or 5, low or 4, high or 2, highest or 1
Default: Normal or 3
sendpdf
Syntax: sendpdf=bool
Description: Specify whether to send the results with the email as an attached PDF or not. For more information about using Splunk's integrated PDF generation functionality, see "Upgrade PDF printing for Splunk Web" in the Installation Manual.
Default: false
sendresults
Syntax: sendresults=bool
Description: Determines whether the results should be included with the email.
Default: false
server
Syntax: server=<string>
Description: If the SMTP server is not local, use this to specify it.
Default: localhost
subject
Syntax: subject=<string>
Description: Specifies the subject line.
Default: "Splunk Results"
width_sort_columns
Syntax: width_sort_columns=<bool>
Description: This is only valid when format=text. Specifies whether the columns should be sorted by their width.
Default: true

Examples

Example 1: Send search results in HTML format with the subject "myresults".

... | sendemail to="elvis@splunk.com,john@splunk.com" format=html subject=myresults server=mail.splunk.com sendresults=true

Example 2: Send search results to the specified email.

... | sendemail to="elvis@splunk.com" sendresults=true

Answers

Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the sendemail command.

PREVIOUS
selfjoin
  NEXT
set

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18


Comments

Wodcock - Thanks for catching that. I have updated the topic to show the defaults.

Jkat54 - Good eyes! I have updated the syntax to remove the duplicates.

Lstewart splunk, Splunker
February 8, 2016

This is missing defaults: graceful, sendpdf, width_sort_columns

Woodcock
February 5, 2016

sendresults appears in the syntax twice. Just being picky at this point... ;-)

Jkat54
November 6, 2015

Thanks for catching that!

Sophy, Splunker
July 18, 2012

Exaclty. This makes no sense. If "sendresults=true" for detail to be sent back, how do these examples provide useful data?

Gstewart
July 11, 2012

How do the examples work, if sendresults defaults to false?

Mallikabachan
June 2, 2012

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters