Hello,
Excellent app by the way. Is there a way to change the order of the columns for the data host availability alert?
Ideally, I would like to have the data_sourcetype
column right next to the data_host
field.
Would it be possible to modify the search to accommodate that?
Thanks in advance.
Hi @jonqkuldeskisecurity !
Thank you 😉
I understand you are talking about the builtin alert named "TrackMe - Alert on data host availability" and the order of the fields in the results.
You can effectively modify the alert up to your needs to include the fields in the order you prefer, therefore take note that Splunk will automatically achieve a copy of the alert provided by the app code (in the default/savedsearches.conf) to a local copy which will contain your customisation.
This is perfectly fine but any change in the default code will not be reflected anymore and you will have to manage it on your own.
However, in the next upcoming release, version 1.2.11, I will include a macro which defines the order of the fields.
Macros are better to be customised in the meaning that a customisation will impact a very specific part of the alert, rather than its full definition.
Let me me know if this does not make sense, and thank you for using TrackMe !
Guilhem
Hi, I really appreciate you getting back to me on this! I can definitely wait until the next release to have this capability. I do have a couple follow-up questions regarding the new version however:
Thanks in advance!
Hi @jonqkuldeskisecurity
To reply:
Guilhem