I'm more familiar with the ServiceNow side of things, but in the alert action, there's a Custom Fields section. You can add additional fields there, eg description=[whatever info you want to pass from Splunk] On the ServiceNow side, you'll have to tweak the Transform Map to map the Description field over from the import set table that incidents are originally created on, to the actual Incident table in ServiceNow. I don't know why description isn't included OOTB, seems like a pretty useful field to populate...
... View more