<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Manager App in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312953#M37443</link>
    <description>&lt;P&gt;Hi Simon, &lt;BR /&gt;
Thank you for the quick answer, I've understood now how to use the display_fields.&lt;BR /&gt;
About the description I would like to be able to see it as an email content, for example:&lt;/P&gt;

&lt;P&gt;Description:&lt;BR /&gt;
1. Test &lt;BR /&gt;
2. Test&lt;/P&gt;

&lt;P&gt;And not &lt;/P&gt;

&lt;P&gt;Description: 1.Test 2.Test&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2017 09:51:24 GMT</pubDate>
    <dc:creator>davidda</dc:creator>
    <dc:date>2017-02-22T09:51:24Z</dc:date>
    <item>
      <title>Alert Manager App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312951#M37441</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
What are the variables I can use the display_fields cell under the incident setting tab?&lt;BR /&gt;
Also, there is a way to make the Alert description more readable it is ignoring my description structure and present it in a single row.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 15:01:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312951#M37441</guid>
      <dc:creator>davidda</dc:creator>
      <dc:date>2017-02-21T15:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Manager App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312952#M37442</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="Example"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2511i7FDC0FC5DBAC0D35/image-size/large?v=v2&amp;amp;px=999" role="button" title="Example" alt="Example" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.&lt;BR /&gt;
Larger screenshot: &lt;A href="https://img42.com/a7nfO"&gt;https://img42.com/a7nfO&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Regarding the description: What do you mean exactly with description?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 09:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312952#M37442</guid>
      <dc:creator>Simon</dc:creator>
      <dc:date>2017-02-22T09:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Manager App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312953#M37443</link>
      <description>&lt;P&gt;Hi Simon, &lt;BR /&gt;
Thank you for the quick answer, I've understood now how to use the display_fields.&lt;BR /&gt;
About the description I would like to be able to see it as an email content, for example:&lt;/P&gt;

&lt;P&gt;Description:&lt;BR /&gt;
1. Test &lt;BR /&gt;
2. Test&lt;/P&gt;

&lt;P&gt;And not &lt;/P&gt;

&lt;P&gt;Description: 1.Test 2.Test&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 09:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312953#M37443</guid>
      <dc:creator>davidda</dc:creator>
      <dc:date>2017-02-22T09:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Manager App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312954#M37444</link>
      <description>&lt;P&gt;I've found how to fix the description as I wanted using HTML Tags.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2017 15:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Alert-Manager-App/m-p/312954#M37444</guid>
      <dc:creator>davidda</dc:creator>
      <dc:date>2017-02-26T15:36:53Z</dc:date>
    </item>
  </channel>
</rss>

