What problem are you trying to solve this way? If you want to adjust criticality of an alert depending on an asset affected - that's the functionality of Enterprise Security.
Hi @danielbb
No, you can only use those items in the dropdown. If you try and "Advanced Edit" the alert to use a field you get a validation error:
The only other thing you might be able to do is manually edit the savedsearches.conf and *try* using a field returned in there, however Your Mileage May Vary. This would also introduce management issues regarding the alert as it might make it impossible to edit in the UI - so whilst Im saying it might be possible, I wouldnt recommend it i'm afraid.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi @danielbb ,
could you better describe your request?
are you speaking of Splunk Enterprise or Enterprise Security?
ciao.
Giuseppe