Other Usage

Link to Alert Results to a Field?

tr_newman
Explorer

I have an alert that fires and while generating the alert, uses appendpipe to collect fields and generate an event in another index for collection by a third party tool.

Is there a way to add the View Results link to the event that's generated so that it can map it in our third party tool to link the analysts back to the original alert?

Labels (1)
0 Karma
1 Solution

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

View solution in original post

0 Karma

tr_newman
Explorer

I figured it out, the search link is saved under the search_link value.

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...