Splunk Enterprise Security

Scheduled search event links

mteverest
New Member

Hi I have a scheduled search in Splunk that get forwarded to ServiceNow and I would like to include the original link which produced the alert as part of the description field for the scheduled search.

For example, let's say I manually searched with the following query and there was only a single result over the last 7 days. If I wanted to share this result to a colleague, I can just copy the full URL from the address bar and send the URL to a colleague via email or chat and they will see it in whatever view I'm in (i.e. Events tab and fast mode).

Search:
index=windows EventCode=4624 LogonType=3 User=john.smith

How can I grab/include the full URL to the event as if I was manually searching in myself in Splunk in the description field?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...