Getting Data In

Need to add _raw content into "Log Event"

fshimaya
Engager

My Splunk alerts use the "Log Event" actions. How do I add the contents of _raw into the "Event" field? I tried $result._raw$ but that doesn't appear to be working. Log Event

Having the result content would be really helpful in the Log Event.

0 Karma

sgontla_splunk
Splunk Employee
Splunk Employee

not sure if you are looking something like " | eval rawevent=_raw"?

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...