<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to move alerts through a workflow in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447185#M7857</link>
    <description>&lt;P&gt;There is no case-management capability in core splunk.  This featureset exists in Splunk's premium app &lt;CODE&gt;Enterprise Security&lt;/CODE&gt; and also in the free &lt;CODE&gt;Alert Manager&lt;/CODE&gt; app in splunkbase.  We are also working on our own premium app for this (as are others, I am sure).&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2019 22:41:44 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-05-06T22:41:44Z</dc:date>
    <item>
      <title>How to move alerts through a workflow</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447183#M7855</link>
      <description>&lt;P&gt;Alarms at first glance, seem a bit limited but I may be missing something.  Tried reading the &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Reviewtriggeredalerts"&gt;docs&lt;/A&gt; and searching around in the community but haven't had luck today.&lt;/P&gt;

&lt;P&gt;I can create them with severity (this is good), have them show in my "triggered alerts" but I cannot find workflow abilities… Choices like "annotate, assign, or close them (aside from delete)".  &lt;/P&gt;

&lt;P&gt;As an example a team would watch a board for an alert and would call-out to a response team.  The team that is on-call or actioning should be able to remove the alerts from the other screen or assign them to individuals to work on (mark as in-progress).&lt;/P&gt;

&lt;P&gt;I've done this in other SIEM's and hope it doesn't require webhooks to an external application, perhaps I can custom do this on a dashboard but would need a bit of guidance.&lt;/P&gt;

&lt;P&gt;Thoughts?  Thank you in advance.  (First time posting)&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 00:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447183#M7855</guid>
      <dc:creator>antb</dc:creator>
      <dc:date>2019-05-05T00:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to move alerts through a workflow</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447184#M7856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;this is a feature that pretty much describes workflow handling in splunk enterprise security, which is a splunk premium solution. You can find more information and the posibility to get a demo here: &lt;A href="https://www.splunk.com/en_us/software/enterprise-security.html"&gt;https://www.splunk.com/en_us/software/enterprise-security.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There is also a more light weight solution to this at splunk base, called alert manager:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2665/"&gt;https://splunkbase.splunk.com/app/2665/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Which seems to realize your mentioned use cases pretty accurate.&lt;/P&gt;

&lt;P&gt;Greetings&lt;/P&gt;

&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 07:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447184#M7856</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2019-05-06T07:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to move alerts through a workflow</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447185#M7857</link>
      <description>&lt;P&gt;There is no case-management capability in core splunk.  This featureset exists in Splunk's premium app &lt;CODE&gt;Enterprise Security&lt;/CODE&gt; and also in the free &lt;CODE&gt;Alert Manager&lt;/CODE&gt; app in splunkbase.  We are also working on our own premium app for this (as are others, I am sure).&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 22:41:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-move-alerts-through-a-workflow/m-p/447185#M7857</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-06T22:41:44Z</dc:date>
    </item>
  </channel>
</rss>

