All Apps and Add-ons

How to use $job.earliestTime$ token in "sendresults" add-on


I am using "sendresults" add-on in "Alert Actions" and tried using $job.earliestTime$ token in the "Message body" section. It works but it shows the value in EPOCH and I want to know how to display it in human readable format.

Labels (1)
0 Karma


Try creating a new field in your alert and passing that in the alert action.

... | eval Time=stftime(job.earliestTime, "%c")
If this reply helps you, Karma would be appreciated.
0 Karma


I tried your suggestion but the search is not recognizing the token "job.earliestTime". Also I dont want to show the extra field in result table.


| eval job.eTime=strftime(job.earliestTime, "%c") 
| table FIELD1, FIELD2, job.eTime


Then I tried calling $result.job.eTime$ in "Alert Actions"

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...