Splunk Enterprise Security

Scheduled search event links

mteverest
New Member

Hi I have a scheduled search in Splunk that get forwarded to ServiceNow and I would like to include the original link which produced the alert as part of the description field for the scheduled search.

For example, let's say I manually searched with the following query and there was only a single result over the last 7 days. If I wanted to share this result to a colleague, I can just copy the full URL from the address bar and send the URL to a colleague via email or chat and they will see it in whatever view I'm in (i.e. Events tab and fast mode).

Search:
index=windows EventCode=4624 LogonType=3 User=john.smith

How can I grab/include the full URL to the event as if I was manually searching in myself in Splunk in the description field?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...