<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on - multi select values in an alert action in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450455#M6243</link>
    <description>&lt;P&gt;But I need to dynamically create those fields from a search results. Is this possible?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Feb 2019 17:07:52 GMT</pubDate>
    <dc:creator>shacharh</dc:creator>
    <dc:date>2019-02-11T17:07:52Z</dc:date>
    <item>
      <title>Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450451#M6239</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm working on an add-on for Splunk. I added an alert action, and I'm adding some fields to it.&lt;BR /&gt;
How can I add a &lt;STRONG&gt;dynamic multi-select&lt;/STRONG&gt; field? The use case - I query Splunk, display the values, and allow the user to select some or all of them. The closest thing I've found is Splunk's &lt;CODE&gt;splunk-search-dropdown&lt;/CODE&gt;, but it is only for single select.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Shachar&lt;/P&gt;</description>
      <pubDate>Sun, 10 Feb 2019 15:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450451#M6239</guid>
      <dc:creator>shacharh</dc:creator>
      <dc:date>2019-02-10T15:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450452#M6240</link>
      <description>&lt;P&gt;would it be of any issue, if you concatenate the multiple values selected by user to something like "value1, value2,value3" and send it your alert actions, where you can act based on value1, 2 3?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 16:39:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450452#M6240</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-11T16:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450453#M6241</link>
      <description>&lt;P&gt;@lakshman239 If you mean that the user would be able to select multiple values, and I'll get them as "value1, value2,value3" in the backend, yes, that would work for me.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 16:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450453#M6241</guid>
      <dc:creator>shacharh</dc:creator>
      <dc:date>2019-02-11T16:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450454#M6242</link>
      <description>&lt;P&gt;when user selects multiple values, save them to a field in an index (which has concatenated values) and give this in your alert action [ one of the field].&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 16:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450454#M6242</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-11T16:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450455#M6243</link>
      <description>&lt;P&gt;But I need to dynamically create those fields from a search results. Is this possible?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 17:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450455#M6243</guid>
      <dc:creator>shacharh</dc:creator>
      <dc:date>2019-02-11T17:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450456#M6244</link>
      <description>&lt;P&gt;Yes, thats possible. As you know what fields are possible (by dynamic selection), you can save them to a field and inside the modalert*.py, you can parse them and extract them to your needs.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450456#M6244</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-27T10:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450457#M6245</link>
      <description>&lt;P&gt;@lakshman239 but how can the user choose the fields? (he needs to choose some or all of them)&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 11:38:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450457#M6245</guid>
      <dc:creator>shacharh</dc:creator>
      <dc:date>2019-02-27T11:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on - multi select values in an alert action</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450458#M6246</link>
      <description>&lt;P&gt;As part of your add-on, I assume you are building a config page and alert UI (where you run a search and show fields in multi-select). The users select them and you save them to another field or index, which is passed as alert actions (pls check alert_actions.conf) and inside your modalert*.py you can then process them. Hope I am thinking along your requirements. If you are using Add-on builder, it will be easy.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 12:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Add-on-multi-select-values-in-an-alert-action/m-p/450458#M6246</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-27T12:01:34Z</dc:date>
    </item>
  </channel>
</rss>

