[Reference: https://docs.splunk.com/Documentation/Splunk/8.2.2/Search/Searchindexes, B is the correct answer because dynamic field values can be specified with syntax within a correlation search. This syntax allows you to insert values from fields returned by the correlation search into alert actions such as email subject or body. For example, inserts the value of the host field into the email. References: [Use dynamic field values in correlation searches in ITSI]]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit