How can I add custom wording to a email alarm? For example instructions to our NOC?
A custom script is the best way to accomplish this currently within Splunk.
See this previous thread -> http://splunk-base.splunk.com/answers/621/email-alert-subject
These may also be interesting:
View solution in original post
I have achieved this by adding a new line to the $SPLUNK_HOME/etc/apps/search/bin/sendemail.py file...but make sure you copy the file first in case it all goes wrong!