<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get the search query time range in the Alert message body in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524429#M9826</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Alert/EmailNotificationTokens#Job_information_tokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Alert/EmailNotificationTokens#Job_information_tokens&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you can use email Notification tokens in your email body.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$job.earliestTime$&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$job.latestTime$&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 14:08:23 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-10-13T14:08:23Z</dc:date>
    <item>
      <title>Get the search query time range in the Alert message body</title>
      <link>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524422#M9825</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement to display the search query time range in the body of the email alert, is there a way i can do that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Search:&lt;/P&gt;&lt;P&gt;index="ABC" source=XYZ earliest=-3month latest=now| table ClientId Restricted Success Rejected Failed Total&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to display the time range that my search considered in the email alert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 13:50:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524422#M9825</guid>
      <dc:creator>dchoubey</dc:creator>
      <dc:date>2020-10-13T13:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Get the search query time range in the Alert message body</title>
      <link>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524429#M9826</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Alert/EmailNotificationTokens#Job_information_tokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Alert/EmailNotificationTokens#Job_information_tokens&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you can use email Notification tokens in your email body.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$job.earliestTime$&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$job.latestTime$&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:08:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524429#M9826</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-10-13T14:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Get the search query time range in the Alert message body</title>
      <link>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524432#M9827</link>
      <description>&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;$job.earliestTime$&lt;/TD&gt;&lt;TD&gt;Initial job start time&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;....the initial job start time is the alert job start time or the "earliest" time the search query time?!?!&lt;/P&gt;&lt;P&gt;or, you can include the whole search query as well (which includes the earliest and latest times)&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;$search$&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;Search string&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Get-the-search-query-time-range-in-the-Alert-message-body/m-p/524432#M9827</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-13T14:26:00Z</dc:date>
    </item>
  </channel>
</rss>

