Alerting

Which field to store meta data about alert begin deployed?

mosh
Explorer

I want to save some meta-data (operational history of the alert (beyond the text description)) along with alert as a json object in a field.  This is from automated  pipelines using sdk (nodejs/python) and POST API  to splunk servers.

Labels (1)
Tags (3)
0 Karma

mosh
Explorer

This has to part of savedsearch (alert/correlation search param), before it is deployed/updated, but should not affect splunk actions in anyway. Otherwise I can manage it myself (outside of splunk) as I do right now.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Once events have been indexed (stored) no new fields can be added.  If you need to store additional information then you have a few options:

  1. Write it to a lookup file
  2. Write it to the KVStore
  3. Write it to a summary index (or a regular index)
---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...