Thanks for the quick reply. I've tested and this solution does not work. I've tested with token "$result.host$" and "$result.src_host$".
My saved search is as follows:
Search
tag::host="atg" tag::host="prod1" source=*/server.log TESTING--SRUFF
Email subject
Splunk Alert: $name$ $result.host$
Latest alert email subject line has "Splunk Alert: <saved search name>" but does not include the hostname of from the server who's log contained the search text. I was expecting to see "Splunk Alert: <saved search name> <server name>".
Thanks.
... View more