What is the complete list of tokens available for the message in the new 6.1 alerts?

Path Finder

I cannot find a complete list of the tokens that are available for the message text in the new Splunk v6.1 alert system.

The online help has some examples like $job.resultCount$ but I cannot find a complete list.

Labels (1)
Tags (2)
1 Solution

Path Finder

In case anyone else's search brings them here first - the new token documentation is here:


Slight update to this link to reflect a more recent version of Splunk:

Quick Reference:

Search Name: $name$
Search Description: $description$
Results Link (reports & alerts): $results_link$
Search String: $search$
Link to saved search: $view_link$

Fields: $result.fieldname$

Job Details

$job.earliestTime$Initial job start time
$job.eventSearch$Subset of the search that appears before any transforming commands
$job.latestTime$Latest time recorded for the search job
$job.messages$List of error and debug messages generated by the search job
$job.resultCount$Search job result count
$job.runDuration$Time, in seconds, for search job completion
$job.sid$Search ID
$job.label$Search job name

Dashboard Label
Dashboard Description: $dashboard.description$



0 Karma

Path Finder

This link now redirects to the main splunk doc page.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...