I am also facing the same issue. Though my search query returns more than 1 rows of results, only the first row of result is taken by default and sent as alert notification in my Slack channel from Splunk Enterprise.
I want only one alert to be triggered as per scheduled time and it show all the results (of respective selected fields).
I want only one alert to be triggered as per scheduled time and it show all the results (of respective selected fields).
Could anyone please help me on this.
Originally posted by @Archana-Karivaratharaj in https://github.com/splunk/slack-alerts/issues/30#issuecomment-1491412102