Alerting

Filter data sended using saved search with action webhook or email action

TISKAR
Builder

Hello Splunker's

I programmed a saved search with a send webhook data action to send the result in json format. I noticed that the data sent contains additional information like app name eand result_link:

INFO -: {"app" => "search", "results_link" => "http: // splk-sh: 8000 / app / search / search? ....

In fact, I don't want to display this information on my results; i searched in advanced actions i found:

action.webhook.command: sendalert $action_name$ results_file="$results.file$" results_link="$results.url$"

i tried to delete result_link but it doesn't work. 

did you encounter this problem on whebook or even email action can be the same.

Thank you

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...