Dashboards & Visualizations

Alert trigger condition token

ryhluc01
Communicator

Is there a token for trigger conditions? The trigger condition option within the alert only tells you the type (i.e numbered or custom) of condition but not the content of the condition.

0 Karma
1 Solution

ryhluc01
Communicator

I was not able to find a token for this purpose. I ended up just manually typing in my condition instead

View solution in original post

0 Karma

ryhluc01
Communicator

I was not able to find a token for this purpose. I ended up just manually typing in my condition instead

0 Karma

niketn
Legend

@ryhluc01 please elaborate your question for the need of token for the community to assist you better. Can Custom trigger condition help you in any way?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

ryhluc01
Communicator

Thank you, I was essentially looking for a quick way to insert the content for my triggered condition directly into the email without having to manually type it out. I was hoping there was a token to use instead.

We have tokens for all sorts of things but I have not found one that will grab the content of the alert trigger.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...