Getting Data In

Need to add _raw content into "Log Event"

fshimaya
Engager

My Splunk alerts use the "Log Event" actions. How do I add the contents of _raw into the "Event" field? I tried $result._raw$ but that doesn't appear to be working. Log Event

Having the result content would be really helpful in the Log Event.

0 Karma

sgontla_splunk
Splunk Employee
Splunk Employee

not sure if you are looking something like " | eval rawevent=_raw"?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...