0

This is simple, however I have been able to find anything at the basic level of "number of rows/records found in query" for use in a Slack notification.

For example to reference the $name$ of the alert, thats the variable. Is there a list of other items? I'm specifically looking for count or rows.

Thanks!

1 Answers1

0

Despite the name, this list of tokens is available outside of email notifications. https://docs.splunk.com/Documentation/Splunk/7.3.0/Alert/EmailNotificationTokens

For a count of rows, use $job.resultCount$.

Other tokens are available at https://docs.splunk.com/Documentation/Splunk/7.3.0/AdvancedDev/ModAlertsLog.

RichG
  • 161
  • 4