Is there a way to get the actual link for the alert when using the Service Now Incident Integration addon, as you would get with the normal Send email option? Thinking it’s a Custom fields setting, but not sure.
https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usecustomsearchcommands
See screenshots.