All Apps and Add-ons

Alert Manager App

davidda
Explorer

Hello,
What are the variables I can use the display_fields cell under the incident setting tab?
Also, there is a way to make the Alert description more readable it is ignoring my description structure and present it in a single row.

Thanks

Tags (1)
0 Karma
1 Solution

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

View solution in original post

0 Karma

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

0 Karma

davidda
Explorer

Hi Simon,
Thank you for the quick answer, I've understood now how to use the display_fields.
About the description I would like to be able to see it as an email content, for example:

Description:
1. Test
2. Test

And not

Description: 1.Test 2.Test

Thank you.

0 Karma

davidda
Explorer

I've found how to fix the description as I wanted using HTML Tags.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...