<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert - Subject - Possible to add host name? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85213#M1176</link>
    <description>&lt;P&gt;My bad, it will add the host in the attached results included in the email, not in the email subject.&lt;/P&gt;

&lt;P&gt;As far as I know there is no option to make the subject dynamic (it's static or populated with the search-name). The only way to go further is to use a custom alert script and manage yourself the email creation.&lt;BR /&gt;
see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2013 18:32:12 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-01-14T18:32:12Z</dc:date>
    <item>
      <title>Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85209#M1172</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is there is a way for me to put the host and server name in the subject line of the alert email? Is it possible at all?&lt;/P&gt;

&lt;P&gt;I have created an alert searching for the keyword "Fatal error". The logs are generated from several host machines from a few different servers. How do I track which host and/or server the "Fatal error" is from?&lt;/P&gt;

&lt;P&gt;The log line looks like this:&lt;/P&gt;

&lt;PRE&gt;
2013-01-08 07:34:49,949 ERROR: Fatal error for something something something &amp;lt;(PID)&amp;gt; ServerName
&lt;/PRE&gt;

&lt;P&gt;Host is one of the extracted fields.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 17:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85209#M1172</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-01-11T17:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85210#M1173</link>
      <description>&lt;P&gt;Anyone ? ? ?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 20:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85210#M1173</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-01-11T20:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85211#M1174</link>
      <description>&lt;P&gt;format your search results and add the required fields&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;mysearch&amp;gt; | table _time host source _raw&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2013 00:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85211#M1174</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-12T00:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85212#M1175</link>
      <description>&lt;P&gt;Thank you for the response. I do not understand how that will add the host name in the subject line of an alert email.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 16:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85212#M1175</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-01-14T16:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85213#M1176</link>
      <description>&lt;P&gt;My bad, it will add the host in the attached results included in the email, not in the email subject.&lt;/P&gt;

&lt;P&gt;As far as I know there is no option to make the subject dynamic (it's static or populated with the search-name). The only way to go further is to use a custom alert script and manage yourself the email creation.&lt;BR /&gt;
see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 18:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85213#M1176</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-14T18:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85214#M1177</link>
      <description>&lt;P&gt;I see. Thanks for confirming. That's what I thought too.&lt;/P&gt;

&lt;P&gt;I have read through that documentation already and didn't look like those custom script parameters get me what I need ... unless there is one alert per host, which I am not going to do.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 19:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85214#M1177</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-01-16T19:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert - Subject - Possible to add host name?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85215#M1178</link>
      <description>&lt;P&gt;Looks like this can be done in version 6.1 and up by adding  $result.host$ in the Subject field.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/235240/include-hostname-in-alert-email-subject.html"&gt;https://answers.splunk.com/answers/235240/include-hostname-in-alert-email-subject.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 18:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Subject-Possible-to-add-host-name/m-p/85215#M1178</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2016-05-31T18:27:52Z</dc:date>
    </item>
  </channel>
</rss>

