Alerting

Which field to store meta data about alert begin deployed?

mosh
Explorer

I want to save some meta-data (operational history of the alert (beyond the text description)) along with alert as a json object in a field.  This is from automated  pipelines using sdk (nodejs/python) and POST API  to splunk servers.

Labels (2)
Tags (3)
0 Karma

mosh
Explorer

This has to part of savedsearch (alert/correlation search param), before it is deployed/updated, but should not affect splunk actions in anyway. Otherwise I can manage it myself (outside of splunk) as I do right now.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Once events have been indexed (stored) no new fields can be added.  If you need to store additional information then you have a few options:

  1. Write it to a lookup file
  2. Write it to the KVStore
  3. Write it to a summary index (or a regular index)
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...