Alerting

Which field to store meta data about alert begin deployed?

mosh
Explorer

I want to save some meta-data (operational history of the alert (beyond the text description)) along with alert as a json object in a field.  This is from automated  pipelines using sdk (nodejs/python) and POST API  to splunk servers.

Labels (1)
Tags (3)
0 Karma

mosh
Explorer

This has to part of savedsearch (alert/correlation search param), before it is deployed/updated, but should not affect splunk actions in anyway. Otherwise I can manage it myself (outside of splunk) as I do right now.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Once events have been indexed (stored) no new fields can be added.  If you need to store additional information then you have a few options:

  1. Write it to a lookup file
  2. Write it to the KVStore
  3. Write it to a summary index (or a regular index)
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...