Hello experts. I'm a Splunk newbie.
I am using the Jira Service Desk simple AddOn to send Splunk alarms to Jira tickets.
We also confirmed that Splunk alarms were successfully raised through Jira tickets. However, sometimes it is the same alarm, but a specific alarm receives the customfield value well, but there are cases where no value is retrieved.
In Splunk, it is confirmed that the value exists, but the value cannot be retrieved. No matter how much I searched, I couldn't find out what the reason was. If the Jira and Splunk field mappings are incorrect, you shouldn't be able to get the value from all tickets, but you can't get it from a specific ticket... What's the problem?
Example here... The Client value is always a value. However, as shown in the images, the customer value does not exist.
[Error Ticket]
[Normal Ticket]