Alerting

Display search results start_time and end_time in email alert subject line

Ravi_c
New Member

Hi,

I need to display the search results start time and end time in the alert email subject line.

How can I do this, I have included $timerange$ in the subject but in the alert email, it was coming as $timerange$ only , please help.

0 Karma

lguinn2
Legend

Here is a list of the variables that you can include in the subject line (you will have to scroll down a bit):

Set up alert actions

Also, try these: $job.earliestTime$ and $job.latestTime$

0 Karma

somesoni2
Revered Legend

There is no straightforward way I guess. Have a look at the similar post.
http://answers.splunk.com/answers/63372/how-to-include-searched-date-or-time-range-in-alert-report

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...