Is there any way to customize the subject line in an SMTP output action or template? Instead of using one of the three pre-canned options of Short, Medium, or Long, none of which allow you to modify their content.
Ideally I'd like to set up smtp output actions and/or templates just like we do reports where I can declare SQL clauses and specify variables to construct a dynamic subject line so the people receiving the email alerts have something more relevant.
Say you have a corelation rule fire when XYZ happens on a firewall or IDS. I'd like to be able to specify the SMTP subject line to say "XYZ on %DeviceHostName%". Or in certain circumstances where your paging out to someone who's oncall that there is an increased trend in something happening, like "Virus Threshold Exceeded, %VirusCount% detections of %virusname% in last hour."
That would be way more helpful than a subject line of: ViewName, AertCategoryName, etc, etc, etc.
Anyone had any luck with this? Any ideas?