All Apps and Add-ons

Alert Manager: How do I get the "tags" field populated?

daniel333
Builder

All,

Just playing around with the Alert Manager app from Splunkbase. Not sure how I get the "tags" field populated? It's not a tags.conf field it seems? Seems it gathered somehow in the data model?

thanks!

Simon
Contributor

Hi daniel

You already gave the answer yourself.
For all the other folks:
Besides the custom alert settings, which can't be changed after an incident has been generated, there are some addition properties which can be changed by alert under Settings -> Incident Settings. These settings apply also for already existing incidents, that's why they are separated from the general alert action settings.

Hope that answers your question.
Simon

0 Karma

Simon
Contributor

Hi Daniel
I'm afraid it's not possible but this is a great idea!
I just created an enhancement request. Have a look at https://github.com/simcen/alert_manager/issues/123 to track progress.

Thanks
Simon

0 Karma

daniel333
Builder

Oh! i see it's an option under incident settings in the GUI. Is there a way to generate this value from my search?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...