<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270214#M4949</link>
    <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;i found this in the Splunk Wiki. Hope this helps.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Splunk_Alert_MIB"&gt;http://wiki.splunk.com/Community:Splunk_Alert_MIB&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;kind regards&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2016 11:12:43 GMT</pubDate>
    <dc:creator>TStrauch</dc:creator>
    <dc:date>2016-10-24T11:12:43Z</dc:date>
    <item>
      <title>Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270213#M4948</link>
      <description>&lt;P&gt;Hi at all,&lt;BR /&gt;
I found the script to send Splunk alerts to an external console (e.g.: IBM Netcool) using SNMP, but does anyone know if there already is a SNMP Splunk MIB to do this?&lt;BR /&gt;
Usually MIB is defined by the hardware or software supplier!&lt;BR /&gt;
Thank you.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 10:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270213#M4948</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-10-24T10:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270214#M4949</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;i found this in the Splunk Wiki. Hope this helps.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Splunk_Alert_MIB"&gt;http://wiki.splunk.com/Community:Splunk_Alert_MIB&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;kind regards&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 11:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270214#M4949</guid>
      <dc:creator>TStrauch</dc:creator>
      <dc:date>2016-10-24T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270215#M4950</link>
      <description>&lt;P&gt;Thank you.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 07:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270215#M4950</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2016-10-25T07:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270216#M4951</link>
      <description>&lt;P&gt;The way i did it in one of my integrations was to send SNMP traps to an external console (eg Netcool) via a python script.&lt;BR /&gt;
So whenever an alert was triggered in Splunk alert action would execute the python script to send the snmp traps. Can you also share how you achieved the integration.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 09:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270216#M4951</guid>
      <dc:creator>soumyasaha25</dc:creator>
      <dc:date>2017-09-18T09:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270217#M4952</link>
      <description>&lt;P&gt;Hi soumyasaha25,&lt;BR /&gt;
We realizad a connector that modify Splunk behaviour, because Splunk alert gives 8 parameters:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"Number of events returned by the saved search" "Search terms" &lt;/LI&gt;
&lt;LI&gt;"Fully qualified search query string" &lt;/LI&gt;
&lt;LI&gt;"Name of the saved search" &lt;/LI&gt;
&lt;LI&gt;"Reason for saved search to trigger alert" &lt;/LI&gt;
&lt;LI&gt;"URL to saved search" &lt;/LI&gt;
&lt;LI&gt;"Tags belonging to the saved search, optional" &lt;/LI&gt;
&lt;LI&gt;"Path on the Splunk Server to a file containing search results"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;but I really need messages contained in the 8th parameter.&lt;/P&gt;

&lt;P&gt;So we created a script that runs when alert is triggered and it perform the following actions:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;it take the 8th parameter from the alert,&lt;/LI&gt;
&lt;LI&gt;it untar file containing alert message from the above path,&lt;/LI&gt;
&lt;LI&gt;it copy message in the alert's 8th parameter of the Splunk MIB,&lt;/LI&gt;
&lt;LI&gt;it send message using Splunk MIB.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In this way the receive can receive the alert message in the Splunk MIB.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 10:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/270217#M4952</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-18T10:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/514782#M9500</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; : One question - thanks for explaining the integration method. One question , where did you put the MIB on - Splunk machine or the external device where Splunk alerts will be trapped ?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 22:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/514782#M9500</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-08-18T22:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there already a SNMP MIB for Splunk that sends Splunk alerts to an external console?</title>
      <link>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/514846#M9505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/140728"&gt;@rashi83&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the scrips must be on the Search Heads, wher you run the alerts because it's and action of the alert:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the external device send its logs to Splunk,&lt;/LI&gt;&lt;LI&gt;Splunk monitor logs running the alert with the defined frequency,&lt;/LI&gt;&lt;LI&gt;Splunk fires the alert where it finds the conditions and run the script that prepare the message and send it to NetCool ot the other destination.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 06:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Is-there-already-a-SNMP-MIB-for-Splunk-that-sends-Splunk-alerts/m-p/514846#M9505</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-19T06:56:40Z</dc:date>
    </item>
  </channel>
</rss>

