Alerting

Can we add specific text in Alerts

xvxt006
Contributor

Hi,

We would like to add alert specific contextual information. is it possible to modify each alert to have custom text in there?

Tags (2)
0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

If you are using the alert to send an email, you can customize the email message with any text you want, as well as tokens to include variables from the search that generated the alert. See Set up alert actions > Email notification in the Alerting Manual.

View solution in original post

stephane_cyrill
Builder

You can create a contextual message for your alert and populate the event corresponding to the alert and the message in and index where you will go and retrieve them after.

to do that you have to buid your alert like this:

|Eval message= or < if(.......) > |table message otherfields|collect index youIndex

after setting your alert as you like where the alert will be triggered, you will have it in yourIndex with your message.

stephane_cyrill
Builder

feel free to vote and accept .....

0 Karma

ChrisG
Splunk Employee
Splunk Employee

If you are using the alert to send an email, you can customize the email message with any text you want, as well as tokens to include variables from the search that generated the alert. See Set up alert actions > Email notification in the Alerting Manual.

xvxt006
Contributor

Nice...Thank you..

0 Karma

stephanefotso
Motivator

Only if you want to send an email message, you can add a message

SGF
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...