Splunk ITSI

How to add a field value from results in ITSI episode review

PotatoDataUser
Explorer

I have setup an episode review that is capturing alerts and generating episodes, so now I want to know if I can add comments to the Episode based on conditions, for example splunk-system-user should check if the status becomes -pending and add a comment : "The details for this are - (fieldvalue) "

for example : if i have a field with name "Version"

I want the system to add a comment like : "The details for this are : 1.2.3"

I tried adding this in rules.

PotatoDataUser_0-1751968736180.png

But when i check the comments i see the comments like this

PotatoDataUser_1-1751968764283.png


Please let me know if you know of any way I can add a field value in the comments.

Thanks in advance.

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...