hi
we have a clustered environment. Is there a way to get where the "watcher" have run? We have putting a same set of watcher ,but needed to ensure only PROD watchers are alerted. Hence wanted to filter on a specific key-word of the "elastic_host" in our logic.
In Splunk , there are default fields like "splunk_server" which comes up with every event. Is there any such fields which may be hidden somewhere for elastic where I can make use upon?