Hello All,
I have a requirement to display the search query time range in the body of the email alert, is there a way i can do that?
Search:
index="ABC" source=XYZ earliest=-3month latest=now| table ClientId Restricted Success Rejected Failed Total
I want to display the time range that my search considered in the email alert.
Thank you
you can use email Notification tokens in your email body.
$job.earliestTime$
$job.latestTime$
$job.earliestTime$ | Initial job start time |
....the initial job start time is the alert job start time or the "earliest" time the search query time?!?!
or, you can include the whole search query as well (which includes the earliest and latest times)
$search$ | Search string |
you can use email Notification tokens in your email body.
$job.earliestTime$
$job.latestTime$