Splunk Enterprise Security

Scheduled search event links

mteverest
New Member

Hi I have a scheduled search in Splunk that get forwarded to ServiceNow and I would like to include the original link which produced the alert as part of the description field for the scheduled search.

For example, let's say I manually searched with the following query and there was only a single result over the last 7 days. If I wanted to share this result to a colleague, I can just copy the full URL from the address bar and send the URL to a colleague via email or chat and they will see it in whatever view I'm in (i.e. Events tab and fast mode).

Search:
index=windows EventCode=4624 LogonType=3 User=john.smith

How can I grab/include the full URL to the event as if I was manually searching in myself in Splunk in the description field?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...