All Apps and Add-ons

Splunk Add-on for ServiceNow: Is it possible to add more columns to results returned by the snoweventstream command?

nhicks
Explorer

When running the |snoweventstream command it returns the columns: "Time of the event", "_time","State","Source","Event Link","Node","Severity","Resource","Type" and "Sys Id". Is there a way to add more columns to the results returned?

For example, in my search, I am looking for PCName. What I would like to do is, when I run the |snoweventstream command, have it return these results.
"Time of the event", "_time","State","Source","Event Link","Node","Severity","Resource","Type","Sys Id" and "PCName"

Is that possible?

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

We are limited by what ServiceNow Api returns.

0 Karma

nhicks
Explorer

So I forgot to add this to my first question. The reason behind wanting to do this is when i send out an email from the alert that contains the |snoweventstream command the fields that i want to send in the email are not part of the returned results so the emails just end up as blank.

So in this example if I put PC name = $result.PCName$ in the email it ends up as PC Name =

0 Karma

nhicks
Explorer

So there is no way to concatenate Splunk search results with the Servicenow results?

something like | snoweventstream PCname or |snoweventstream." ".PCname or a similar command?

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...
OSZAR »