Alerting

What is the complete list of tokens available for the message in the new 6.1 alerts?

raoul
Path Finder

I cannot find a complete list of the tokens that are available for the message text in the new Splunk v6.1 alert system.

The online help has some examples like $job.resultCount$ but I cannot find a complete list.

Labels (1)
Tags (2)
1 Solution

matthewhaswell
Path Finder

In case anyone else's search brings them here first - the new token documentation is here: http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/EmailNotificationTokens

rivium_ro_mc
Explorer

Slight update to this link to reflect a more recent version of Splunk: https://docs.splunk.com/Documentation/Splunk/8.2.5/Alert/EmailNotificationTokens

Quick Reference:

Search Name: $name$
Search Description: $description$
Results Link (reports & alerts): $results_link$
Search String: $search$
Link to saved search: $view_link$

Fields: $result.fieldname$

Job Details

$job.earliestTime$Initial job start time
$job.eventSearch$Subset of the search that appears before any transforming commands
$job.latestTime$Latest time recorded for the search job
$job.messages$List of error and debug messages generated by the search job
$job.resultCount$Search job result count
$job.runDuration$Time, in seconds, for search job completion
$job.sid$Search ID
$job.label$Search job name


Dashboard Label
$dashboard.label$
Dashboard Description: $dashboard.description$

 

 

SteveIves1
Engager

The documentation about the use of tokens talks about using them in emails. Can they be used in other alert integrations such as Moogsoft?

0 Karma

matthewhaswell
Path Finder

This link now redirects to the main splunk doc page.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...