I have setup an episode review that is capturing alerts and generating episodes, so now I want to know if I can add comments to the Episode based on conditions, for example splunk-system-user should check if the status becomes -pending and add a comment : "The details for this are - (fieldvalue) "
for example : if i have a field with name "Version"
I want the system to add a comment like : "The details for this are : 1.2.3"
I tried adding this in rules.
But when i check the comments i see the comments like this
Please let me know if you know of any way I can add a field value in the comments.
Thanks in advance.
Unfortunately "Add a comment" does not support field token replacement.
See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Unfortunately "Add a comment" does not support field token replacement.
See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing