Hello! We have a requierment to create an alert for one of the cloud application data. The following fields are like account name, account id etc should be sent to the repective RemediationContactEmail id. we are able to create an alert with all the above with csv attachment by using command sendemail However we observed that for particular set of results , if the recipients are same , in that case they will be receiving email for each results. For example We tried below sample query to make some sample event sets using makeresults : | makeresults | eval id="12345" | eval Account_ID=1234567 | eval Remediation_Contact_Email="abc123@xyz.com" | append [| makeresults | eval id="67890" | eval Account_ID=4567895 | eval Remediation_Contact_Email="abc123@xyz.com" ] | append [| makeresults | eval id="13579" | eval Account_ID=6785432 | eval Remediation_Contact_Email="abc123@xyz.com" ] | map [ makeresults | eval id="$id$" | eval Account_ID=$Account_ID$ | eval Remediation_Contact_Email="$Remediation_Contact_Email$" | fields - _time | sendemail to=$Remediation_Contact_Email$ subject="Test Sendemail" message=" Hello, There is an alert for your account id : $id$ account id : $Account_ID$ Regards, xyz Security Operation Team" maxinputs=10000 sendcsv=true inline=true format=csv priority=1 ] Here the recipient "abc123@xyz.com" received 3 different emails for each result with attachments as shown in the bellow screenshot. Any help or guidance will be much appreciated here to group all the relevant results in data set with respect to remidiation contact email id and send their results in single attachment. We tried to group it using stats command however the attachment doesn’t look good as it will have a single row with all results for that particular email.we have more number of RemediationContactEmail id for each Account group in data set so if there are any 10 alerts triggered for one respective RemediationContactEmail id all the 10 alerts should be consolidated and grouped from data set then send it to that particullar recepient as one attachment rather than sending 10 different emails
... View more