Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I send just the value of token $job.resultCount$ to a webhook?

$
0
0
We have a simple alert with a Webook action assigned to it with an endpoint is OMI. Search: index=xyz TCP_ERROR appName="jojothedolphin" Alert: If number of results > 10 After the alert is triggered, field and values I want to send as my payload are stored in tokens: $trigger_date$ $trigger_time$ $alert.severity$ $job.resultCount$ But I am pulling my hair out trying to figure out how to access them and their value. I cannot get them to display in a table (or any other way which would then become my payload. Help! Damon

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>