<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to get custom alert fields, or just alert.raw on custom outgoing webhook? (Any-Incident event type)? in Splunk On-Call</title>
    <link>https://community.splunk.com/t5/Splunk-On-Call/How-to-get-custom-alert-fields-or-just-alert-raw-on-custom/m-p/638272#M92</link>
    <description>&lt;P&gt;hi, we have a bunch of fields that show up in the Splunk Oncall/VictorOps UI. under either "Alert Details &amp;gt; Alert Data &amp;gt; Alert Fields" or "Annotations" (screenshot below) that i'm hoping to insert into the payload body of a&amp;nbsp;&lt;A href="https://help.victorops.com/knowledge-base/custom-outbound-webhooks/#suggested-variables" target="_self"&gt;custom outbound webhook&lt;/A&gt;&amp;nbsp; of "Any-Incident" event type.&lt;/P&gt;&lt;P data-unlink="true"&gt;When using the VictorOps API i only see the custom fields present under the "raw" field of the &lt;A href="https://portal.victorops.com/public/api-docs.html#!/Alerts/get_api_public_v1_alerts_uuid" target="_self"&gt;GET Alert response&lt;/A&gt;.&lt;/P&gt;&lt;P data-unlink="true"&gt;I see in the &lt;A href="https://help.victorops.com/knowledge-base/incident-fields-glossary/" target="_self"&gt;Incident Fields&lt;/A&gt; support page some mention of custom_fields, which makes me think perhaps we could add those to payload with something like ${{ALERT.custom_fields}}, or ${{ALERT.raw}}, but at least when i tried those nothing was populated on the webhook payload for it&lt;/P&gt;&lt;P data-unlink="true"&gt;Since i havent been able to find documentation on how to add these custom fields, annotations, or raw alert payload to the webhook payload body and they dont appear within the suggested variables, does someone know how we would add those to the webhook body or if thats possible?&amp;nbsp; Or do i need to pull them from the Alert.raw field myself and if so how would i get that raw field on the webhook payload?&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Thanks!&lt;/P&gt;&lt;P&gt;"&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-02 at 3.30.52 PM.png" style="width: 474px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24668i93DF643A9C259C6E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-04-02 at 3.30.52 PM.png" alt="Screenshot 2023-04-02 at 3.30.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Apr 2023 17:40:03 GMT</pubDate>
    <dc:creator>whyNot</dc:creator>
    <dc:date>2023-04-04T17:40:03Z</dc:date>
    <item>
      <title>How to get custom alert fields, or just alert.raw on custom outgoing webhook? (Any-Incident event type)?</title>
      <link>https://community.splunk.com/t5/Splunk-On-Call/How-to-get-custom-alert-fields-or-just-alert-raw-on-custom/m-p/638272#M92</link>
      <description>&lt;P&gt;hi, we have a bunch of fields that show up in the Splunk Oncall/VictorOps UI. under either "Alert Details &amp;gt; Alert Data &amp;gt; Alert Fields" or "Annotations" (screenshot below) that i'm hoping to insert into the payload body of a&amp;nbsp;&lt;A href="https://help.victorops.com/knowledge-base/custom-outbound-webhooks/#suggested-variables" target="_self"&gt;custom outbound webhook&lt;/A&gt;&amp;nbsp; of "Any-Incident" event type.&lt;/P&gt;&lt;P data-unlink="true"&gt;When using the VictorOps API i only see the custom fields present under the "raw" field of the &lt;A href="https://portal.victorops.com/public/api-docs.html#!/Alerts/get_api_public_v1_alerts_uuid" target="_self"&gt;GET Alert response&lt;/A&gt;.&lt;/P&gt;&lt;P data-unlink="true"&gt;I see in the &lt;A href="https://help.victorops.com/knowledge-base/incident-fields-glossary/" target="_self"&gt;Incident Fields&lt;/A&gt; support page some mention of custom_fields, which makes me think perhaps we could add those to payload with something like ${{ALERT.custom_fields}}, or ${{ALERT.raw}}, but at least when i tried those nothing was populated on the webhook payload for it&lt;/P&gt;&lt;P data-unlink="true"&gt;Since i havent been able to find documentation on how to add these custom fields, annotations, or raw alert payload to the webhook payload body and they dont appear within the suggested variables, does someone know how we would add those to the webhook body or if thats possible?&amp;nbsp; Or do i need to pull them from the Alert.raw field myself and if so how would i get that raw field on the webhook payload?&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Thanks!&lt;/P&gt;&lt;P&gt;"&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-02 at 3.30.52 PM.png" style="width: 474px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24668i93DF643A9C259C6E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-04-02 at 3.30.52 PM.png" alt="Screenshot 2023-04-02 at 3.30.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 17:40:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-On-Call/How-to-get-custom-alert-fields-or-just-alert-raw-on-custom/m-p/638272#M92</guid>
      <dc:creator>whyNot</dc:creator>
      <dc:date>2023-04-04T17:40:03Z</dc:date>
    </item>
  </channel>
</rss>

