I want to save some meta-data (operational history of the alert (beyond the text description)) along with alert as a json object in a field. This is from automated pipelines using sdk (nodejs/python) and POST API to splunk servers.
This has to part of savedsearch (alert/correlation search param), before it is deployed/updated, but should not affect splunk actions in anyway. Otherwise I can manage it myself (outside of splunk) as I do right now.
Once events have been indexed (stored) no new fields can be added. If you need to store additional information then you have a few options: