Hi!
I use alerts with Trigger Actions --> send email, and I need to insert the date in the subject in the email.
I tried to use the token $result._time$ print in unix format.
Could you help me please for change the format, for example, "Splunk alert: 13/08/2019 11:23:65"?
Regards.
As the last step of you search you can format you time to what ever you need. Just add this after your search:
Use this if you want to use the event time ( _time
)
| eval email_time = strftime(_time,"%d/%m/%Y %H:%M:%S")
Or this if you want the current time ( now()
) when the search was executed
| eval email_time = strftime(now(),"%d/%m/%Y %H:%M:%S")
The different its just the source field being used to generate the timestamp and then use strftime to format it however you want.
You can then use $result.email_time$ in your alert.
As the last step of you search you can format you time to what ever you need. Just add this after your search:
Use this if you want to use the event time ( _time
)
| eval email_time = strftime(_time,"%d/%m/%Y %H:%M:%S")
Or this if you want the current time ( now()
) when the search was executed
| eval email_time = strftime(now(),"%d/%m/%Y %H:%M:%S")
The different its just the source field being used to generate the timestamp and then use strftime to format it however you want.
You can then use $result.email_time$ in your alert.
Hi! @diogofgm in my search add the command fields with the new field 'email_time' so I can pass the token to email
Thanks you, Regards!