<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scripted Alert to third party event managemet in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144815#M2345</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
we are setting up some alerts based on a vendor script to automatically populate an Event Management Console.&lt;BR /&gt;
The problem is that we need to extract some informations (=fileds) from Splunk raw data included in the alert to pass it as a parameter to the script itself, so we will be able to pupulate correctly the Event management console.&lt;/P&gt;

&lt;P&gt;Example syntax:&lt;/P&gt;

&lt;P&gt;custom_bin.sh -n @event.management.console:port -b host_extracted_from_splunk_data -u user_extracted_from_splunk_data &lt;/P&gt;

&lt;P&gt;where:&lt;/P&gt;

&lt;P&gt;custom_bin.sh is our third party script&lt;/P&gt;

&lt;P&gt;-n @event.management.console:port is the event management console fqdn:port&lt;/P&gt;

&lt;P&gt;-b host_extracted_from_splunk_data is the host field indexed by splunk present in the specific record we need to extract to&lt;/P&gt;

&lt;P&gt;-u user_extracted_from_splunk_data is the user filed extracted ... like the host field&lt;/P&gt;

&lt;P&gt;Any hint on how we can achieve it?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:05:14 GMT</pubDate>
    <dc:creator>bizza</dc:creator>
    <dc:date>2020-09-28T17:05:14Z</dc:date>
    <item>
      <title>Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144815#M2345</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
we are setting up some alerts based on a vendor script to automatically populate an Event Management Console.&lt;BR /&gt;
The problem is that we need to extract some informations (=fileds) from Splunk raw data included in the alert to pass it as a parameter to the script itself, so we will be able to pupulate correctly the Event management console.&lt;/P&gt;

&lt;P&gt;Example syntax:&lt;/P&gt;

&lt;P&gt;custom_bin.sh -n @event.management.console:port -b host_extracted_from_splunk_data -u user_extracted_from_splunk_data &lt;/P&gt;

&lt;P&gt;where:&lt;/P&gt;

&lt;P&gt;custom_bin.sh is our third party script&lt;/P&gt;

&lt;P&gt;-n @event.management.console:port is the event management console fqdn:port&lt;/P&gt;

&lt;P&gt;-b host_extracted_from_splunk_data is the host field indexed by splunk present in the specific record we need to extract to&lt;/P&gt;

&lt;P&gt;-u user_extracted_from_splunk_data is the user filed extracted ... like the host field&lt;/P&gt;

&lt;P&gt;Any hint on how we can achieve it?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144815#M2345</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2020-09-28T17:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144816#M2346</link>
      <description>&lt;P&gt;The eighth parameter passed to the alert script is a path to the search results. You can examine those to extract whatever info you need. &lt;A href="http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system"&gt;http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 13:04:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144816#M2346</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-16T13:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144817#M2347</link>
      <description>&lt;P&gt;Hi Martin, thank for your answer.&lt;BR /&gt;
I need to extract from results some fields and use they as a parameter for the third party script.&lt;BR /&gt;
Something like the host, the username for example.&lt;BR /&gt;
Do you know if it's possible?&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 13:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144817#M2347</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2014-07-16T13:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144818#M2348</link>
      <description>&lt;P&gt;The path points at a gzipped CSV file, you can pick whatever field you need from that.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 14:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144818#M2348</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-16T14:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144819#M2349</link>
      <description>&lt;P&gt;thanks martin, i solved just parsing the csv with a perl script.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 10:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144819#M2349</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2014-07-17T10:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144820#M2350</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;

&lt;P&gt;do you have an example of the script you have been using here?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2015 14:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144820#M2350</guid>
      <dc:creator>rsiekermann_spl</dc:creator>
      <dc:date>2015-07-24T14:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Alert to third party event managemet</title>
      <link>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144821#M2351</link>
      <description>&lt;P&gt;The &lt;STRONG&gt;&lt;A href="http://dev.splunk.com/goto/devguide"&gt;Splunk Developer’s Guide&lt;/A&gt;&lt;/STRONG&gt; and the accompanying &lt;A href="https://splunkbase.splunk.com/app/1934/"&gt;Splunk Reference App&lt;/A&gt; might be helpful in answering your question. The book is available in both &lt;A href="http://amzn.to/1G8OCu2"&gt;paperback&lt;/A&gt; and &lt;A href="http://amzn.to/1Re7IPL"&gt;Mobi&lt;/A&gt; from Amazon.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/80iB20E9007668028CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
It was designed by a Splunk dev team to help you learn how to build, test, and deploy apps - The reference app (named PAS) showcases proven practices using the Splunk Developer Platform and includes &lt;A href="https://github.com/splunk/splunk-ref-pas-code"&gt;code&lt;/A&gt; that you can download, reuse and even contribute to, code walkthroughs as well as the associated unit and acceptance &lt;A href="https://github.com/splunk/splunk-ref-pas-test"&gt;tests&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;The featured example demonstrates how to monitor various document repositories (current and future). Managers and auditors can use the app to see who has viewed, modified, deleted, or downloaded documents or other artifacts from various sources, detect suspicious behaviors, and analyze trends.&lt;/P&gt;

&lt;P&gt;Currently an updated version is under development that will expand the functionality, so even if it’s not relevant now you might want to keep checking to see what’s been added.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 19:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Scripted-Alert-to-third-party-event-managemet/m-p/144821#M2351</guid>
      <dc:creator>rcorbisier_splu</dc:creator>
      <dc:date>2015-10-21T19:29:45Z</dc:date>
    </item>
  </channel>
</rss>

