Hi,
This is what I am getting for %SPLUNK_ARG_8%:C:/ProgramFiles/Splunk/var/run/splunk/dispatch/rt_scheduler_adminsearch_errorcode20_at_1431029291_8.55/per_result_alert/tmp_8.csv.gz
When I go to
//localhost:8000/app/search/@go?sid=rt_scheduler_adminsearch_errorcode20_at_1431029291_8.55
The link brings up the search! Thanks for your help. Arg 6 is still not working for me through a script, but I can just scrape the info from arg 8.
Thanks again
... View more