<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert Manager App - How to create a incident per result (row) in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Manager-App-How-to-create-a-incident-per-result-row/m-p/542729#M10285</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to create an incident within the Alert Manager App per result row of the generating search.&lt;BR /&gt;Let's say I have a search "Failed transactions by host". The result table looks like this:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;_time&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;failed_transactions&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;2021-03-07 12:55:01&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host_a&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;2021-03-07 12:55:01&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host_b&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is easy to create an incident for "failed transactions" in general. But I would like to create incidents per host, that can be tracked individually.&amp;nbsp; I tried to achieve it by using $result.host$ as the title, but this did not work.&lt;BR /&gt;&lt;BR /&gt;Does anyone know whether this is possible?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Mar 2021 12:01:02 GMT</pubDate>
    <dc:creator>peterschloenske</dc:creator>
    <dc:date>2021-03-07T12:01:02Z</dc:date>
    <item>
      <title>Alert Manager App - How to create a incident per result (row)</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Manager-App-How-to-create-a-incident-per-result-row/m-p/542729#M10285</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to create an incident within the Alert Manager App per result row of the generating search.&lt;BR /&gt;Let's say I have a search "Failed transactions by host". The result table looks like this:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;_time&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;failed_transactions&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;2021-03-07 12:55:01&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host_a&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;2021-03-07 12:55:01&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;host_b&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is easy to create an incident for "failed transactions" in general. But I would like to create incidents per host, that can be tracked individually.&amp;nbsp; I tried to achieve it by using $result.host$ as the title, but this did not work.&lt;BR /&gt;&lt;BR /&gt;Does anyone know whether this is possible?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 12:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Manager-App-How-to-create-a-incident-per-result-row/m-p/542729#M10285</guid>
      <dc:creator>peterschloenske</dc:creator>
      <dc:date>2021-03-07T12:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Manager App - How to create a incident per result (row)</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Manager-App-How-to-create-a-incident-per-result-row/m-p/542818#M10289</link>
      <description>&lt;P&gt;I did not recognize that I saved it as report instead as an alert. As an alert, I can set "trigger for each result" to get it work&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 12:10:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Manager-App-How-to-create-a-incident-per-result-row/m-p/542818#M10289</guid>
      <dc:creator>peterschloenske</dc:creator>
      <dc:date>2021-03-08T12:10:10Z</dc:date>
    </item>
  </channel>
</rss>

