Notable events are indexed summary events. There is no modifying an event once indexed in Splunk. You have two options.
1. If you want fields indexed in the notable event make your code a custom search command.
2. Make your code an adaptive response that indexes the data for subsequent searching, or populates a lookup that you shim onto the notable events.
See this for shimming on a lookup
http://www.georgestarcher.com/splunk-enterprise-security-enhancing-incident-review/
... View more