Hi at all,
I have to create an Heartbeat Alert that contains three fields:
Thank You.
Bye.
Giuseppe
You can use $server.serverName$
in the email alert settings: http://docs.splunk.com/Documentation/Splunk/6.5.1/Alert/EmailNotificationTokens#Server_tokens
In an actual search, you can use | rest splunk_server=local /services/server/info
to grab the search head you're running on.
You can use $server.serverName$
in the email alert settings: http://docs.splunk.com/Documentation/Splunk/6.5.1/Alert/EmailNotificationTokens#Server_tokens
In an actual search, you can use | rest splunk_server=local /services/server/info
to grab the search head you're running on.
Thank you, your rest command answers to my question.
Bye.
Giuseppe