Splunk ITSI

How to add a field value from results in ITSI episode review

PotatoDataUser
Explorer

I have setup an episode review that is capturing alerts and generating episodes, so now I want to know if I can add comments to the Episode based on conditions, for example splunk-system-user should check if the status becomes -pending and add a comment : "The details for this are - (fieldvalue) "

for example : if i have a field with name "Version"

I want the system to add a comment like : "The details for this are : 1.2.3"

I tried adding this in rules.

PotatoDataUser_0-1751968736180.png

But when i check the comments i see the comments like this

PotatoDataUser_1-1751968764283.png


Please let me know if you know of any way I can add a field value in the comments.

Thanks in advance.

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...