All Apps and Add-ons

Alert Manager App

davidda
Explorer

Hello,
What are the variables I can use the display_fields cell under the incident setting tab?
Also, there is a way to make the Alert description more readable it is ignoring my description structure and present it in a single row.

Thanks

Tags (1)
0 Karma
1 Solution

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

View solution in original post

0 Karma

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

0 Karma

davidda
Explorer

Hi Simon,
Thank you for the quick answer, I've understood now how to use the display_fields.
About the description I would like to be able to see it as an email content, for example:

Description:
1. Test
2. Test

And not

Description: 1.Test 2.Test

Thank you.

0 Karma

davidda
Explorer

I've found how to fix the description as I wanted using HTML Tags.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...