<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add custom fields to the alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608455#M14112</link>
    <description>&lt;P&gt;No you can't do this by default for this you have to create your own custom alert app. I would recommend use this custom add-on app it will help you to create the alert addon&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/2962/" target="_blank"&gt;https://splunkbase.splunk.com/app/2962/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;also have a look on this video it will help you&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.youtube.com/watch?v=UqJAc7rpFmQ&amp;amp;t=185s" target="_blank"&gt;https://www.youtube.com/watch?v=UqJAc7rpFmQ&amp;amp;t=185s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if it helps&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2022 13:30:56 GMT</pubDate>
    <dc:creator>Siddharth</dc:creator>
    <dc:date>2022-08-05T13:30:56Z</dc:date>
    <item>
      <title>How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/607979#M14095</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are looking to add a custom field to our alerts to BigPanda. Is there a way to add fields natively or a workaround done by any Splunk users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Kay&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 23:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/607979#M14095</guid>
      <dc:creator>kkawatra</dc:creator>
      <dc:date>2022-08-02T23:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608011#M14098</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248224"&gt;@kkawatra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;your question is just a little vague!&lt;/P&gt;&lt;P&gt;In general, answer is yes.&lt;/P&gt;&lt;P&gt;Could you better describe your request?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are you speaking of fields from the search of from a lookup?&lt;/LI&gt;&lt;LI&gt;are you speaking of fixed fields?&lt;/LI&gt;&lt;LI&gt;are you speaking of adding custom fields to the results&amp;nbsp; or to the message?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in other words, please share your search and better describe your request.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 06:53:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608011#M14098</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-03T06:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608189#M14107</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all I'm new to Splunk, so pardon my lack of knowledge.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, I want to say adding custom fields to the results&lt;/P&gt;&lt;P&gt;The idea is to send splunk alerts to BigPanda. But for BigPanda to accept those alerts and further move along to create ticket and attach any TSGs, its looking for very specific fields. So, I was wondering if we can send the payload with custom fields via webhook or we can send it over BigPanda integration(preferred).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kay&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 21:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608189#M14107</guid>
      <dc:creator>kkawatra</dc:creator>
      <dc:date>2022-08-03T21:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608219#M14108</link>
      <description>&lt;P&gt;An alert is triggered by conditions being satisfied by the results of a search - the search can contain additional fields (as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;says) simply by using, for example, the eval command or lookup command.&lt;/P&gt;&lt;P&gt;Start by creating a search that produces the results you want in your alert.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 06:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608219#M14108</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-08-04T06:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608224#M14109</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248224"&gt;@kkawatra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;said, you have two ways to add custom fields to your search:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;eval command, if you have few and fixed values to add,&lt;/LI&gt;&lt;LI&gt;lookup if you have many or variable values to add.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;some sample to better understand:&lt;/P&gt;&lt;P&gt;if you have to add e.g. the name of the customer, you could add:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval customer="customer1"&lt;/LI-CODE&gt;&lt;P&gt;in this way all the events will have this fixed field.&lt;/P&gt;&lt;P&gt;If you would e.g. add the location of a server taken from a lookup called perimeter.csv, you have to find a key (e.g. "host") and all the lookup command:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| lookup perimeter.csv host OUTPUT location
| table _time &amp;lt;all_your_fields&amp;gt; location&lt;/LI-CODE&gt;&lt;P&gt;In additio, if you need to have fixed names for the fields, you could use the "rename" command.&lt;/P&gt;&lt;P&gt;If you aren't expert in SPL, you could follow the Splunk Search Tutorial (&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial&lt;/A&gt;) that theaches you about SPL.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 07:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608224#M14109</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-04T07:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608455#M14112</link>
      <description>&lt;P&gt;No you can't do this by default for this you have to create your own custom alert app. I would recommend use this custom add-on app it will help you to create the alert addon&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/2962/" target="_blank"&gt;https://splunkbase.splunk.com/app/2962/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;also have a look on this video it will help you&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.youtube.com/watch?v=UqJAc7rpFmQ&amp;amp;t=185s" target="_blank"&gt;https://www.youtube.com/watch?v=UqJAc7rpFmQ&amp;amp;t=185s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if it helps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 13:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608455#M14112</guid>
      <dc:creator>Siddharth</dc:creator>
      <dc:date>2022-08-05T13:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom fields to the alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608493#M14113</link>
      <description>&lt;P&gt;This worked, thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 15:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-add-custom-fields-to-the-alert/m-p/608493#M14113</guid>
      <dc:creator>kkawatra</dc:creator>
      <dc:date>2022-08-05T15:46:19Z</dc:date>
    </item>
  </channel>
</rss>

