Splunk ITSI

Splunk IT Service Intelligence: Is it possible to customize the Description of Notable Event Group?

harshal_chakran
Builder

Hi,
In Splunk IT Service Intelligence (ITSI), can we customize the 'description' section or add a new section which appears after clicking ITSI - Notable Event Group to show some extra level of information about the events in separate lines?
The same which we can see in 'details' section of Notable Events- Raw View.

Does Notable Events Action SDK provides that feature? As I am not able to understand whether it helps to customize only the actions or we can also update the Notable Events- Group View GUI with extra level of information.

0 Karma
1 Solution

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@harshal_chakranarayan - Did the answer provided by hjauch help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

0 Karma

allisonwalther
Path Finder

Can you inject html in that field? So say create a clickable link as part of the description..?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...