Alerting

Display search results start_time and end_time in email alert subject line

Ravi_c
New Member

Hi,

I need to display the search results start time and end time in the alert email subject line.

How can I do this, I have included $timerange$ in the subject but in the alert email, it was coming as $timerange$ only , please help.

0 Karma

lguinn2
Legend

Here is a list of the variables that you can include in the subject line (you will have to scroll down a bit):

Set up alert actions

Also, try these: $job.earliestTime$ and $job.latestTime$

0 Karma

somesoni2
Revered Legend

There is no straightforward way I guess. Have a look at the similar post.
http://answers.splunk.com/answers/63372/how-to-include-searched-date-or-time-range-in-alert-report

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...