The Alert:
(host="x.x.x.254" OR host="x.x.x.253" OR host="x.x.x.54" OR host="x.x.x.253") "%PIM-5-NBRCHG" DOWN interface "port-channel*"
The Output:
2015-01-07T10:01:29-0500 <189>294832: 307113: Jan 7 10:01:29 EST: %PIM-5-NBRCHG: neighbor x.x.x.73 DOWN on interface Port-channel15 non DR
So the alert is fine, but how do I know which of the four host its coming from, need to see "host" with the alert. New to this, so appreciate the help.
If you're showing the raw event in the alert email, add following to the end if the alert search
| table host, _raw
If you're showing the raw event in the alert email, add following to the end if the alert search
| table host, _raw