Splunk IT Service Intelligence

Splunk IT Service Intelligence: Is it possible to customize the Description of Notable Event Group?

harshal_chakran
Builder

Hi,
In Splunk IT Service Intelligence (ITSI), can we customize the 'description' section or add a new section which appears after clicking ITSI - Notable Event Group to show some extra level of information about the events in separate lines?
The same which we can see in 'details' section of Notable Events- Raw View.

Does Notable Events Action SDK provides that feature? As I am not able to understand whether it helps to customize only the actions or we can also update the Notable Events- Group View GUI with extra level of information.

0 Karma
1 Solution

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

View solution in original post

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@harshal_chakranarayan - Did the answer provided by hjauch help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

hjauch_splunk
Splunk Employee
Splunk Employee

You can set the Group Title and Group Description in the aggregation policy to Static value and then specify the text you want to use or you can use field substitution to substitute a field value by using this format %fieldname%. In this way you can customize the group description.

Also, you can click the Grouped Events tab to see the individual notable events in the group.

0 Karma

allisonwalther
Path Finder

Can you inject html in that field? So say create a clickable link as part of the description..?

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...