Dashboards & Visualizations

How do I send just the value of token $job.resultCount$ to a webhook?

damonmanni
Path Finder

We have a simple alert with a Webook action assigned to it with an endpoint is OMI.

Search: index=xyz TCP_ERROR appName="jojothedolphin"
Alert: If number of results > 10

After the alert is triggered, field and values I want to send as my payload are stored in tokens:
$trigger_date$
$trigger_time$
$alert.severity$
$job.resultCount$

But I am pulling my hair out trying to figure out how to access them and their value. I cannot get them to display in a table (or any other way which would then become my payload. Help!
Damon

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...