I have a Splunk Add-on built to fetch events/alerts. I am currently getting fields for the alerts in the following way:
event["server_host"] = helper.settings.get("server_host")
event["alert_title"] = helper.settings.get("search_name")
event["alert_description"] = helper.settings.get("configuration").get("alert_description")
I need to get additional fields such as: Search String, Trigger Time, and Runbook.
Is it documented anywhere, or do any of you know what the backend names for these fields are or how to get them?
Appreciate any help 🙂
 
		
		
		
		
		
	
			
		
		
			
					
		@addOnGuy - I don't know if its very clear from your description what exactly that you are building.
But here is the document for helper functions - https://docs.splunk.com/Documentation/AddonBuilder/4.5.0/UserGuide/PythonHelperFunctions
If you are building Custom Alert Action with Add-on Builder then this should help - https://docs.splunk.com/Documentation/AddonBuilder/4.5.0/UserGuide/CreateAlertActions
I hope this helps!!
