<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Security / OpsGenie integration issue in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456444#M6457</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.&lt;EM&gt;X&lt;/EM&gt;) and/or last version of Splunk Enterprise Security (5.2.&lt;EM&gt;X&lt;/EM&gt;).&lt;/P&gt;

&lt;P&gt;We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed &lt;A href="https://splunkbase.splunk.com/app/3759/"&gt;OpsGenie Splunk app&lt;/A&gt;, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Do you have any advice?&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;

&lt;P&gt;Alex.&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2019 07:45:22 GMT</pubDate>
    <dc:creator>AlexeySh</dc:creator>
    <dc:date>2019-05-16T07:45:22Z</dc:date>
    <item>
      <title>Splunk Enterprise Security / OpsGenie integration issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456444#M6457</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.&lt;EM&gt;X&lt;/EM&gt;) and/or last version of Splunk Enterprise Security (5.2.&lt;EM&gt;X&lt;/EM&gt;).&lt;/P&gt;

&lt;P&gt;We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed &lt;A href="https://splunkbase.splunk.com/app/3759/"&gt;OpsGenie Splunk app&lt;/A&gt;, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Do you have any advice?&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;

&lt;P&gt;Alex.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 07:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456444#M6457</guid>
      <dc:creator>AlexeySh</dc:creator>
      <dc:date>2019-05-16T07:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security / OpsGenie integration issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456445#M6458</link>
      <description>&lt;P&gt;Alexey, did you ever figure this out? We just implemented OpsGenie too. None of my existing correlation searches have the options of apply the OpsGenie trigger action in ES. However, I can see the OpsGenie trigger action in the Search and Reporting app alerts. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 15:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456445#M6458</guid>
      <dc:creator>dzayas</dc:creator>
      <dc:date>2019-11-14T15:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security / OpsGenie integration issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456446#M6459</link>
      <description>&lt;P&gt;Hi @dzayas ,&lt;/P&gt;

&lt;P&gt;Unfortunately, it's impossible to integrate ES correlation searches with OpsGenie app (or at least it was back in May 2019). Correlation Search is not the same type of instances as a Search Alert in Splunk, and after checking with OpsGenie support we've found that nothing's happen on OpsGenie side when a Correlation Search is triggered.&lt;/P&gt;

&lt;P&gt;The workaround we finally used was to synchronise Splunk ES Notable Events and OpsGenie alerts via email. For each Splunk ES Notable Event we added a "Send Email" response action and added an OpsGenie email as a recipient. Then in OpsGenie we set up an alert creation for each Notable Event based on Sender and Email Title (unique for each Notable Event).&lt;/P&gt;

&lt;P&gt;Unfortunately, in this case you loose some of ES capabilities, like flexible alert Urgency (based on Notable Event urgency and asset's urgency). Instead you have to select a fixed urgency for each alert in OpsGenie. But it's better than nothing&lt;/P&gt;

&lt;P&gt;Hope it was helpful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  &lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 16:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456446#M6459</guid>
      <dc:creator>AlexeySh</dc:creator>
      <dc:date>2019-11-14T16:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security / OpsGenie integration issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456447#M6460</link>
      <description>&lt;P&gt;It's definitely helpful!&lt;/P&gt;

&lt;P&gt;Looks like that it's definitely the case where OpsGenie and ES don't work together. I took a look at the internal logs and when the correlation searches invoke the opsgenie app, it fails:&lt;/P&gt;

&lt;P&gt;ERROR sendmodalert - Error in 'sendalert' command: Alert action "opsgenie" not found.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 16:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-OpsGenie-integration-issue/m-p/456447#M6460</guid>
      <dc:creator>dzayas</dc:creator>
      <dc:date>2019-11-14T16:16:25Z</dc:date>
    </item>
  </channel>
</rss>

