All Apps and Add-ons

Alert Manager App

davidda
Explorer

Hello,
What are the variables I can use the display_fields cell under the incident setting tab?
Also, there is a way to make the Alert description more readable it is ignoring my description structure and present it in a single row.

Thanks

Tags (1)
0 Karma
1 Solution

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

View solution in original post

0 Karma

Simon
Contributor

Hi
display_fields contains a space-delimited list of field names. The field names are used to pick fields from the results of the alert and will be shown in the incident posture dashboard when you expand an incident by clicking the icon at the beginning of a row:
Example

In my exmple, I added 'user' to display_fields, which is a field in the results triggering the alert.
Larger screenshot: https://img42.com/a7nfO

Regarding the description: What do you mean exactly with description?

0 Karma

davidda
Explorer

Hi Simon,
Thank you for the quick answer, I've understood now how to use the display_fields.
About the description I would like to be able to see it as an email content, for example:

Description:
1. Test
2. Test

And not

Description: 1.Test 2.Test

Thank you.

0 Karma

davidda
Explorer

I've found how to fix the description as I wanted using HTML Tags.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...