Hi everyone,
I'm trying to create a search that i can display the notable information. But i have a problema, when i display de rule_description, the field value apears with tokens. how can i recover the description with the token value?
http://docs.splunk.com/Documentation/ES/5.1.1/Admin/Expandtoken