<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implementing a Incident management system in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64274#M885</link>
    <description>&lt;P&gt;I think, that the easiest way to "integrate" a ticketing tool with Splunk ist to set up alerts and trigger a script that will create a ticket in your existing ticketing tool ( via whatever interface the tool offers).There is documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Alert/Configuringscriptedalerts"&gt; here&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Enterprise Security app does have a workflow implemented to deal with the notable events(which are more or less incidents) that are created. Both of those are part of ES though and not available out of the box in a standard Splunk installation. &lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2013 11:31:25 GMT</pubDate>
    <dc:creator>chris</dc:creator>
    <dc:date>2013-06-14T11:31:25Z</dc:date>
    <item>
      <title>Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64272#M883</link>
      <description>&lt;P&gt;We are planning to implement INCIDENT MANAGEMENT system in Splunk. &lt;BR /&gt;
For that we need to integrate a ticketing tool with Splunk. &lt;BR /&gt;
I have seen the Splunk Enterprise Security app which is similar to what we try to implement.&lt;BR /&gt;
Is there any ideas on this ?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 10:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64272#M883</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-06-14T10:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64273#M884</link>
      <description>&lt;P&gt;Get the Enterprise Security app? &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 11:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64273#M884</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-06-14T11:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64274#M885</link>
      <description>&lt;P&gt;I think, that the easiest way to "integrate" a ticketing tool with Splunk ist to set up alerts and trigger a script that will create a ticket in your existing ticketing tool ( via whatever interface the tool offers).There is documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Alert/Configuringscriptedalerts"&gt; here&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Enterprise Security app does have a workflow implemented to deal with the notable events(which are more or less incidents) that are created. Both of those are part of ES though and not available out of the box in a standard Splunk installation. &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 11:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64274#M885</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2013-06-14T11:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64275#M886</link>
      <description>&lt;P&gt;I need to set up a forwarder in the ticket tool server . there i need to configure the scripted inputs to get the ticket detials and populate in Splunk.&lt;BR /&gt;
Problem here is Ticket Tool domain control is with another stream of business , where they provide access to install UF.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 12:49:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64275#M886</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-06-14T12:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64276#M887</link>
      <description>&lt;P&gt;Without installing forwarder , cant we achieve this?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 12:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64276#M887</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-06-14T12:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64277#M888</link>
      <description>&lt;P&gt;Thats cool. But , will i be getting the conf files and other property files ?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 13:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64277#M888</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-06-14T13:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a Incident management system</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64278#M889</link>
      <description>&lt;P&gt;Oh, if you want to have ticketing information in Splunk it will depend on the ticketing tool and it's interfaces. If there is an interface that is exposed to the network (REST ... ) you might be able to get the information from a different machine than the ticketing server.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2013 21:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Implementing-a-Incident-management-system/m-p/64278#M889</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2013-06-14T21:14:19Z</dc:date>
    </item>
  </channel>
</rss>

