How to add a column to an alert?

Path Finder

Hi Guys,

my question is  Can priority (the regular P1/P2/P3 column) and job alias from the pw_map lookup be added to this alert as additional columns? I’ve recently started seeing some ingest issues with a few queues, and these columns would help with escalation and determining downstream impacts.

Labels (1)
0 Karma


Hi @majilan1,

if the fields to add (priority and job) are fields of the lookup you're using, you can add them to your results adding a values option for each of them to the stats command, something like this:

| stats latest(curdepth) as curdepth first(curdepth) as firstCur count as event_count sum(over_threshold) values(priority) AS Priority values(job) AS Job



0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...