Splunk ITSI

Splunk IT Service Intelligence: Is it possible to customize the Description of Notable Event Group?

harshal_chakran
Builder

Hi,
In Splunk IT Service Intelligence (ITSI), can we customize the 'description' section or add a new section which appears after clicking ITSI - Notable Event Group to show some extra level of information about the events in separate lines?
The same which we can see in 'details' section of Notable Events- Raw View.

Does Notable Events Action SDK provides that feature? As I am not able to understand whether it helps to customize only the actions or we can also update the Notable Events- Group View GUI with extra level of information.

0 Karma
1 Solution

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@harshal_chakranarayan - Did the answer provided by hjauch help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

0 Karma

allisonwalther
Path Finder

Can you inject html in that field? So say create a clickable link as part of the description..?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...