[lookup_entity_contact_details(3)] args = entity_key, alarm, severity definition = lookup itsi_entities _key as entity_key OUTPUT _itsi_informational_lookups \ | eval _itsi_informational_lookups = mvfilter(match(_itsi_informational_lookups, "alert_*")) \ | rex field=_itsi_informational_lookups "(alert_routing=(?.*))?(alert_email=(?.*))?(alert_oncall_routing_key=(?.*))?(alert_custom_param=(?.*))?(alert_snow_assignment_group=(?.*))?" \ | foreach t_* [| eval <>=coalesce(<>,<>)] iseval = 0 [itew_get_splunk_base_uri] definition = "Update macro itew_get_splunk_base_uri with Splunk Base URI. (I.E. https://splunkserver)" iseval = 0