Knowledge Management

Add the search ID to my search results

forbushbl
Engager

Is it possible to add the search ID for the currently running search to the search results?

I have a report that populates a summary index and I have an alert running against the summary index which triggers a webhook. Here is the flow.

scheduled report --> summary index --> alert --> webhook

I would like to capture the search ID from the scheduled report somehow and store that in the summary index so that I could build a link back to the job results for the scheduled report. I figure if that if there is someway to access this ID in my search pipeline, I can just include it in my scheduled report and it will end up in the summary index.

Any help would be appreciated.

0 Karma
1 Solution

somesoni2
Revered Legend

You can include |addinfo command in your summary index search which gives info_sid field which contains current job SID. See more on addinfo command here:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Addinfo

View solution in original post

somesoni2
Revered Legend

You can include |addinfo command in your summary index search which gives info_sid field which contains current job SID. See more on addinfo command here:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Addinfo

forbushbl
Engager

This is exactly what I was looking for, thanks!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...