I cannot find a complete list of the tokens that are available for the message text in the new Splunk v6.1 alert system.
The online help has some examples like $job.resultCount$
but I cannot find a complete list.
In case anyone else's search brings them here first - the new token documentation is here: http://docs.splunk.com/Documentation/Splunk/6.6.2/Alert/EmailNotificationTokens
Slight update to this link to reflect a more recent version of Splunk: https://docs.splunk.com/Documentation/Splunk/8.2.5/Alert/EmailNotificationTokens
Quick Reference:
Search Name: $name$
Search Description: $description$
Results Link (reports & alerts): $results_link$
Search String: $search$
Link to saved search: $view_link$
Fields: $result.fieldname$
Job Details
$job.earliestTime$ | Initial job start time |
$job.eventSearch$ | Subset of the search that appears before any transforming commands |
$job.latestTime$ | Latest time recorded for the search job |
$job.messages$ | List of error and debug messages generated by the search job |
$job.resultCount$ | Search job result count |
$job.runDuration$ | Time, in seconds, for search job completion |
$job.sid$ | Search ID |
$job.label$ | Search job name |
Dashboard Label: $dashboard.label$
Dashboard Description: $dashboard.description$
The documentation about the use of tokens talks about using them in emails. Can they be used in other alert integrations such as Moogsoft?
This link now redirects to the main splunk doc page.