Open simcen opened 8 years ago
I think it's the same.
The title column could replace $result.field1$ by this value but column category, subcategory and tags doesn't.
This is normal ?
I was looking to achieve something similar.
I have a simplified search in Splunk which passes multiple alerts to Alert Manager and it would be nice to pass category & subcategory through to be captured and to use.
https://answers.splunk.com/answers/395666/alert-manager-tags.html