Alerting

How to include time field in email message body?

Murali
Explorer

Hi All,

I'm setting an alert and sending email notification to my inbox.

I have a field called Time and basically it calculates the duration. Example:  "25 minutes ago"    

Hence , when I include the field in the message , like below:

$result.Time$   

I get message in my inbox in seconds. 
Example: 

Host abcd CPU usage reached 97% 1680502445 . Please investigate.

So if you look here , the 1680502445 is the time duration in seconds.

It suppose to pick the summarized time as per the column result. 


Murali_0-1680504445252.png

Please help  how can I get the same output like what I have gathered in the Time1 column. 

 

Thanks




Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Murali,

could you share your search?

probably the issue is in the Time formatiing, e.g. you could add at the end of your search:

| eval Time=tostring(Time, "duration")

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Murali,

could you share your search?

probably the issue is in the Time formatiing, e.g. you could add at the end of your search:

| eval Time=tostring(Time, "duration")

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Murali,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...