<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PagerDuty incomplete results received in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323748#M38747</link>
    <description>&lt;P&gt;Hi Woodcock,&lt;BR /&gt;
It's just a scheduled search that looks for specific patterns in the security device logs and if there are any matches, it sends the results to the pager duty app and email recipients.  Unfortunately I'm very limited in the info I can provide as this is customer data but if there is anything specific you need to know, then I'll provide what I can.  The only thing we add to the pagerduty app is the API key.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 27 Feb 2017 07:21:38 GMT</pubDate>
    <dc:creator>cdstealer</dc:creator>
    <dc:date>2017-02-27T07:21:38Z</dc:date>
    <item>
      <title>PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323746#M38745</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
We use PagerDuty for security results for the oncall security personnel.  Unfortunately the alerts received by PagerDuty are incomplete.  Only the first event is being received.  Also, if there are multiple results, the results in pagerduty are also wrong.  The first splunk result returned 3 usernames, pagerduty says 5 and it contains duplicates.&lt;/P&gt;

&lt;P&gt;The splunk server is running 6.3.0 (we are unable to upgrade it currently) and the pagerduty app, both version 1.0 &amp;amp; 1.1 do the same.&lt;/P&gt;

&lt;P&gt;I have attached both the splunk results and the pageduty received results.  Unfortunately nearly all details needed to be obscured, but hopefully they will show what I mean.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="splunk results"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2539i4C13A4FC10C66A24/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk results" alt="splunk results" /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="pagerduty results"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2540iA9F8BA61D89E6C26/image-size/large?v=v2&amp;amp;px=999" role="button" title="pagerduty results" alt="pagerduty results" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Steve&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 11:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323746#M38745</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2017-02-23T11:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323747#M38746</link>
      <description>&lt;P&gt;You will need to explain the exact method and configuration file details on how you are getting those events into Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 16:43:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323747#M38746</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-23T16:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323748#M38747</link>
      <description>&lt;P&gt;Hi Woodcock,&lt;BR /&gt;
It's just a scheduled search that looks for specific patterns in the security device logs and if there are any matches, it sends the results to the pager duty app and email recipients.  Unfortunately I'm very limited in the info I can provide as this is customer data but if there is anything specific you need to know, then I'll provide what I can.  The only thing we add to the pagerduty app is the API key.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 07:21:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323748#M38747</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2017-02-27T07:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323749#M38748</link>
      <description>&lt;P&gt;I am talking about the details regarding "it sends results to pagerduty".  Obviously something is misconfigured there but you have given us absolutely no details there.  You didn't even show us the alert configuration from &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt;, which might give us some idea of how that part works.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 20:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323749#M38748</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-28T20:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323750#M38749</link>
      <description>&lt;P&gt;Hi Woodcock, Here is a savedsearch that we've used.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    [00_pagerduty_test]
    action.email.include.results_link = 0
    action.email.inline = 1
    action.email.message.alert = Multiple Failed please investigate
    action.email.sendcsv = 1
    action.email.sendresults = 1
    action.pagerduty = 1
    alert.severity = 4
    alert.suppress = 0
    alert.track = 1
    auto_summarize.dispatch.earliest_time = -1d@h
    counttype = number of events
    cron_schedule = * * * * *
    dispatch.earliest_time = -60m@m
    dispatch.latest_time = @m
    enableSched = 1
    quantity = 0
    relation = greater than
    search = index=f5 attack_type="*Other application activity*" response_code=200 username!="XXX*" (ip_client!="xxx.xxx.xxx.xxx" OR ip_client="xxx.xxx.xxx.xxx" OR ip_client!="xxx.xxx.xxx.xxx/19" OR ip_client!="xxx.xxx.xxx.xxx/20" OR ip_client="xxx.xxx.xxx.xxx" OR ip_client="xxx.xxx.xxx.xxx/24" OR ip_client!="xxx.xxx.xxx.xxx/19" OR ip_client!="xxx.xxx.xxx.xxx/18" OR ip_client!="xxx.xxx.xxx.xxx/16" OR ip_client!="xxx.xxx.xxx.xxx/17" OR ip_client="xxx.xxx.xxx.xxx/19" OR ip_client!="xxx.xxx.xxx.xxx/26" OR ip_client!="xxx.xxx.xxx.xxx" OR ip_client!="xxx.xxx.xxx.xxx" OR ip_client!="xxx.xxx.xxx.xxx/24" OR ip_client!="xxx.xxx.xxx.xxx/24" OR ip_client!="xxx.xxx.xxx.xxx/24" OR ip_client!="xxx.xxx.xxx.xxx/24" OR ip_client!="xxx.xxx.xxx.xxx/24") sig_names!="*XXXXXXXXXX*" | stats  dc(username) AS distinctUsers values(username) by ip_client, uri  | where  distinctUsers &amp;gt; 20
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As I mentioned previously, the only config we have done for the PagerDuty app is to add the API key that gets inserted into the URL it uses to send the results to, so I'm unsure as to what we possibly could have misconfigured.  But I have an open mind &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 09:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323750#M38749</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2017-03-02T09:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323751#M38750</link>
      <description>&lt;P&gt;If that is truly all the configuration that there is, I don't see any way to proceed other than to get Pagerduty involved.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 18:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323751#M38750</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-02T18:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323752#M38751</link>
      <description>&lt;P&gt;agreed.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  Thank you for you time, it's appreciated.  Once I have this resolved, I'll update with the answer.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 06:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323752#M38751</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2017-03-06T06:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323753#M38752</link>
      <description>&lt;P&gt;Run into this issue myself, by default the Pagerduty integration for Splunk deduplicates events on Search.&lt;/P&gt;

&lt;P&gt;In PagerDuty -:&lt;/P&gt;

&lt;P&gt;Services → Integrations → Integrations for Splunk → Edit integration&lt;/P&gt;

&lt;P&gt;Under 'deduplicate on' options list -:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Search  &amp;lt;- default option&lt;/LI&gt;
&lt;LI&gt;Component&lt;/LI&gt;
&lt;LI&gt;Host&lt;/LI&gt;
&lt;LI&gt;Source&lt;/LI&gt;
&lt;LI&gt;If open incident - attach results to it&lt;/LI&gt;
&lt;LI&gt;Don’t deduplicate&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If you select 'Don't deduplicate' you should find Pagerduty generate an incident for each event (if desired).&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 16:19:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323753#M38752</guid>
      <dc:creator>gdsahine</dc:creator>
      <dc:date>2019-02-27T16:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323754#M38753</link>
      <description>&lt;P&gt;Make sure that you report back here what the final resolution is when PagerDuty gets you the answer.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 06:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323754#M38753</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-01T06:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: PagerDuty incomplete results received</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323755#M38754</link>
      <description>&lt;P&gt;This is EXACTLY the answer I was looking for.  Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 20:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/PagerDuty-incomplete-results-received/m-p/323755#M38754</guid>
      <dc:creator>rmyerspin</dc:creator>
      <dc:date>2019-08-27T20:46:51Z</dc:date>
    </item>
  </channel>
</rss>

