Splunk ITSI

Splunk IT Service Intelligence: Is it possible to customize the Description of Notable Event Group?

harshal_chakran
Builder

Hi,
In Splunk IT Service Intelligence (ITSI), can we customize the 'description' section or add a new section which appears after clicking ITSI - Notable Event Group to show some extra level of information about the events in separate lines?
The same which we can see in 'details' section of Notable Events- Raw View.

Does Notable Events Action SDK provides that feature? As I am not able to understand whether it helps to customize only the actions or we can also update the Notable Events- Group View GUI with extra level of information.

0 Karma
1 Solution

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@harshal_chakranarayan - Did the answer provided by hjauch help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

0 Karma

allisonwalther
Path Finder

Can you inject html in that field? So say create a clickable link as part of the description..?

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...