Other Usage

Link to Alert Results to a Field?

tr_newman
Explorer

I have an alert that fires and while generating the alert, uses appendpipe to collect fields and generate an event in another index for collection by a third party tool.

Is there a way to add the View Results link to the event that's generated so that it can map it in our third party tool to link the analysts back to the original alert?

Labels (1)
0 Karma
1 Solution

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

View solution in original post

0 Karma

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...