Other Usage

Link to Alert Results to a Field?

tr_newman
Explorer

I have an alert that fires and while generating the alert, uses appendpipe to collect fields and generate an event in another index for collection by a third party tool.

Is there a way to add the View Results link to the event that's generated so that it can map it in our third party tool to link the analysts back to the original alert?

Labels (1)
0 Karma
1 Solution

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

View solution in original post

0 Karma

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...