<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add multiple rows while creating Incident through splunk in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546257#M37536</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant use csv or I can append result in single row because these are Exception messages and ol&amp;nbsp; will be different.&lt;/P&gt;&lt;P&gt;There could be 15 rows also.&lt;/P&gt;&lt;P&gt;Is there any way that if search alert result in 5 rows&lt;/P&gt;&lt;P&gt;one incident will be created and all the 5 rows will be appended to it.&lt;/P&gt;&lt;P&gt;Is any functionality there .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 15:41:55 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2021-03-31T15:41:55Z</dc:date>
    <item>
      <title>How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546224#M37526</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have one requirement.&lt;/P&gt;&lt;P&gt;I am creating Incident through splunk alerts using SAHARA.&lt;/P&gt;&lt;P&gt;This issue I am facing is:&lt;/P&gt;&lt;P&gt;Below is my query:&lt;/P&gt;&lt;P&gt;index=abc&amp;nbsp; ns=xyz|stats count by app_name|eval f1="khus"&lt;/P&gt;&lt;P&gt;The result of the query is this:&lt;/P&gt;&lt;P&gt;app_name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;f1&lt;/P&gt;&lt;P&gt;abc&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; khus&lt;/P&gt;&lt;P&gt;xyx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; khus&lt;/P&gt;&lt;P&gt;But when I creating incident I am only getting first row in my incident not the second row&lt;/P&gt;&lt;P&gt;I have passed like this in unique ID&lt;/P&gt;&lt;P&gt;$result.app_name$ $result.f1$&lt;/P&gt;&lt;P&gt;Can someone guide me on this&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 14:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546224#M37526</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-03-31T14:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546228#M37527</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;You can set&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;Trigger&lt;/STRONG&gt; to &lt;STRONG&gt;For each result&lt;/STRONG&gt; under &lt;STRONG&gt;Trigger Conditions&lt;/STRONG&gt; on the alert edit page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this reply helps you, a like would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 14:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546228#M37527</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T14:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546248#M37531</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this way 2 Incidents are created for each row.&lt;/P&gt;&lt;P&gt;I want only one Incident should be there and 2nd should be append to it.&lt;/P&gt;&lt;P&gt;Because they are from the same result .&lt;/P&gt;&lt;P&gt;Can you guide me is that possible&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546248#M37531</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-03-31T15:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546252#M37534</link>
      <description>&lt;P&gt;You can attach results as csv file OR make fields multivalued so that all the events fit into on erow.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=abc  ns=xyz | stats count by app_name | eval f1="khus" | stats values(*) as *&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546252#M37534</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T15:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546257#M37536</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cant use csv or I can append result in single row because these are Exception messages and ol&amp;nbsp; will be different.&lt;/P&gt;&lt;P&gt;There could be 15 rows also.&lt;/P&gt;&lt;P&gt;Is there any way that if search alert result in 5 rows&lt;/P&gt;&lt;P&gt;one incident will be created and all the 5 rows will be appended to it.&lt;/P&gt;&lt;P&gt;Is any functionality there .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546257#M37536</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-03-31T15:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546262#M37539</link>
      <description>&lt;P&gt;Yes you can, try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=abc  ns=xyz | stats count by app_name | eval f1="khus" | streamstats count as temp | eval temp=floor(count/5) | stats values(*) as * by temp | fields - temp&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546262#M37539</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T15:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546271#M37540</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with this query as well:&lt;/P&gt;&lt;P&gt;index=abc&amp;nbsp; ns=blazegateway|stats count by app_name|eval f1="khushi"| streamstats count as temp | eval temp=floor(count/3) | stats values(*) as * by temp | fields - temp&lt;/P&gt;&lt;P&gt;I am still getting 3 rows&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 16:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546271#M37540</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-03-31T16:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546272#M37541</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=abc  ns=blazegateway|stats count by app_name | eval f1="khushi" | streamstats count as temp | eval temp=floor(count/3) | stats list(*) as * by temp | fields - temp&lt;/LI-CODE&gt;&lt;P&gt;Post some data if you don't get result as you expect.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 16:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546272#M37541</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T16:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546276#M37542</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with this query also I am getting 3 rows.&lt;/P&gt;&lt;P&gt;Is that possible that I can create one&amp;nbsp; incident and then append rest of the rows in it.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 16:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546276#M37542</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-03-31T16:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to add multiple rows while creating Incident through splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546339#M37553</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want like if 2 rows are coming in search result for alert then both rows should come in same incident&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suppose these are the result I am getting:&lt;/P&gt;&lt;P&gt;F1&amp;nbsp; &amp;nbsp; &amp;nbsp;appname&lt;/P&gt;&lt;P&gt;k&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; d&lt;/P&gt;&lt;P&gt;c&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; g&lt;/P&gt;&lt;P&gt;Then when creating incident in uniquefield when I type $result.F1$ $result.appname$&lt;/P&gt;&lt;P&gt;Then both F1 and appname should come on same incident&lt;/P&gt;&lt;P&gt;But currently I am getting only one in incident&lt;/P&gt;&lt;P&gt;Can you guide me on this&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 08:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-multiple-rows-while-creating-Incident-through-splunk/m-p/546339#M37553</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-04-01T08:20:59Z</dc:date>
    </item>
  </channel>
</rss>

