I understand you are talking about the builtin alert named "TrackMe - Alert on data host availability" and the order of the fields in the results.
You can effectively modify the alert up to your needs to include the fields in the order you prefer, therefore take note that Splunk will automatically achieve a copy of the alert provided by the app code (in the default/savedsearches.conf) to a local copy which will contain your customisation.
This is perfectly fine but any change in the default code will not be reflected anymore and you will have to manage it on your own.
However, in the next upcoming release, version 1.2.11, I will include a macro which defines the order of the fields.
Macros are better to be customised in the meaning that a customisation will impact a very specific part of the alert, rather than its full definition.
Let me me know if this does not make sense, and thank you for using TrackMe !