Hi all,
When a alert fires I have it such that the ticket adds the full list of events returned from the search into a CSV file, which is fine, but I am wanting to output say the first 5 events from the search into the description of the jira ticket similarly into a table format. Is that possible?
As far as i've seen its either a single ticket per result or as in my current deployment, single ticket, single event in description but the entire results in attached CSV file.
First time asking a question, but the splunk community has been so helpful and insightful i've manage to go this long without asking one.