Splunk ITSI

How to add a field value from results in ITSI episode review

PotatoDataUser
Explorer

I have setup an episode review that is capturing alerts and generating episodes, so now I want to know if I can add comments to the Episode based on conditions, for example splunk-system-user should check if the status becomes -pending and add a comment : "The details for this are - (fieldvalue) "

for example : if i have a field with name "Version"

I want the system to add a comment like : "The details for this are : 1.2.3"

I tried adding this in rules.

PotatoDataUser_0-1751968736180.png

But when i check the comments i see the comments like this

PotatoDataUser_1-1751968764283.png


Please let me know if you know of any way I can add a field value in the comments.

Thanks in advance.

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @PotatoDataUser 

Unfortunately "Add a comment" does not support field token replacement.

See the docs at https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/detect-and-.... for more details.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...