Splunk IT Service Intelligence

Splunk IT Service Intelligence: Is it possible to customize the Description of Notable Event Group?

harshal_chakran
Builder

Hi,
In Splunk IT Service Intelligence (ITSI), can we customize the 'description' section or add a new section which appears after clicking ITSI - Notable Event Group to show some extra level of information about the events in separate lines?
The same which we can see in 'details' section of Notable Events- Raw View.

Does Notable Events Action SDK provides that feature? As I am not able to understand whether it helps to customize only the actions or we can also update the Notable Events- Group View GUI with extra level of information.

0 Karma
1 Solution

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@harshal_chakranarayan - Did the answer provided by hjauch help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

0 Karma

allisonwalther
Path Finder

Can you inject html in that field? So say create a clickable link as part of the description..?

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...