Thanks for the quick reply. I've tested and this solution does not work. I've tested with token "$result.host$" and "$result.src_host$".
My saved search is as follows:
tag::host="atg" tag::host="prod1" source=*/server.log TESTING--SRUFF
Splunk Alert: $name$ $result.host$
Latest alert email subject line has "Splunk Alert: <saved search name>" but does not include the hostname of from the server who's log contained the search text. I was expecting to see "Splunk Alert: <saved search name> <server name>".
Just for sanity's sake, see if that token works for you in the alert body.
$result.host$ means insert from the results, the value of the field named host. There are some oddities for some cases in that token, but source and host should just work.