All Apps and Add-ons

Alert Manager App

davidda
Explorer

Hello,
What are the variables I can use the display_fields cell under the incident setting tab?
Also, there is a way to make the Alert description more readable it is ignoring my description structure and present it in a single row.

Thanks

Tags (1)
0 Karma
1 Solution

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

View solution in original post

0 Karma

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

0 Karma

davidda
Explorer

Hi Simon,
Thank you for the quick answer, I've understood now how to use the display_fields.
About the description I would like to be able to see it as an email content, for example:

Description:
1. Test
2. Test

And not

Description: 1.Test 2.Test

Thank you.

0 Karma

davidda
Explorer

I've found how to fix the description as I wanted using HTML Tags.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...