Alerting

How do I add host and description of error code in telegram alert?

sphiwee
Contributor

I have the below query for an alert, but the result does not add host or description in the result, how can i achieve this?

 

sphiwee_0-1658678846219.png

 

Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

There are two reasons why the host and description fields are not shown.

1) The stats command removed them.  stats is a transforming command that only passes on the field explicitly mention - in this case count and status.

2) The table command only displays the caption field.

The fixes for host are pretty straightforward - add the field to the stats and table commands.

... | stats count by host, status
...
| table host, caption

Adding the description field likely can be done in a similar manner, but the screenshot tells us nothing about that field so it's hard to say for sure.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

There are two reasons why the host and description fields are not shown.

1) The stats command removed them.  stats is a transforming command that only passes on the field explicitly mention - in this case count and status.

2) The table command only displays the caption field.

The fixes for host are pretty straightforward - add the field to the stats and table commands.

... | stats count by host, status
...
| table host, caption

Adding the description field likely can be done in a similar manner, but the screenshot tells us nothing about that field so it's hard to say for sure.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...