Hi Everyone. Apologies if this answer is on the forum somewhere. We are trying to pass a field value to an alert title which will be used by the Pagerduty integration, which uses the title of the alert as the title of the Pagerduty Incident.
We have tried $result.field_name$ & $field_name$ - with no joy. $result.field_name$ works no problem when using it with the custom details section for the integration.
This is the Pagerduty guide if anyone needs it for reference: https://www.pagerduty.com/docs/guides/splunk-integration-guide/
Really appreciate any help.
Thanks, Sam