I have a similar problem as in http://answers.splunk.com/questions/9375/email-alert-actions-how-to-remove-default-fields-from-each-email
I have tried the answer provided (both of them) and they do not do what I need.
The problem is that I only want to send an email if events are returned but using the sendmail option it sends the mail every time the alert is scheduled. This does not seem possible without a custom script.