Dashboards & Visualizations

Pass string/token to email alert text

jdrohen
New Member

I have a search
"%UC_CALLMANAGER-6-DeviceUnregistered" "DeviceType=90" OR "DeviceType=73"

Which correctly matches the below entry and I have an alert so send an email notification. I would like to pass a string from the syslog text (DeviceName=JK-Test) in the email message but can’t seem to get it pass. When I expand the syslog in search it says DeviceName is JK-Test. In my email message I have tried:

email text:
$Result.DeviceName$ test line 1
"$event.DeviceName$" test line 2
$DeviceName$ test line 3
$result.devicename$ test line 4

Is there a format to where I can pass that info?

search result:
Feb 25 16:17:26 myserver.local Feb 25 2020 22:17:26.527 UTC : %UC_CALLMANAGER-6-DeviceUnregistered: %[DeviceName=JK-Test][IPAddress=1.1.1.1][Protocol=RouteList][DeviceType=90][Description=Test Hunt Group][Reason=8][IPAddrAttributes=0][AppID=Cisco CallManager][ClusterID=StandAloneCluster][NodeID=myserver]: Device unregistered

0 Karma

masonmorales
Influencer
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...