Splunk IT Service Intelligence

Not able to pass field value to notable event(ITSI) script action splunk

AniPrag
Engager

Hi All,

I am trying to pass filed value to a customize script but some how not able to do that. Ex: i am trying to pass Hostname in the script but as per document $result.Hostname is not working... i also tried below option as well

In alert_actions.conf

param.name = $result.Hostname$

showing error invalid stanza

then call the script action

action.py

host = settings.get('name')


any thing Now working.... if there could be any help..

0 Karma

szhou_splunk
Splunk Employee
Splunk Employee

Hi, @AniPrag have you tried %HostName% in stanza?

0 Karma

AniPrag
Engager

@harishalipaka I have already tried that option its not working... Just printing $result.HostName$ nothing else.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...