Alerting

Configure Alert with specific parameters and pass that data as Trigger Action

larryleeroberts
Path Finder

I am attempting to find the best way to start sending alerts from Splunk to Netcool OMNIbus and I am finding it a bit challenging.
One issue I am having is figuring out how to configure Splunk to pass specific information when an Alert Action fires.

For example....
One of the parameters we require are teams to pass when sending an event to OMNIbus is call "OnCallGroup".
Example: OnCallGroup=ProductionServices

I need a way when setting up an Alert Action in Splunk to say that one of the parameters it should pass is OnCallGroup. I see no way to add such extra information to the configuration of the Alert or Trigger Actions.

Any ideas?

Thanks!

0 Karma
1 Solution

hgehrts_splunk
Splunk Employee
Splunk Employee

Hi

You can send some of the information into an alert action but not the results from the query. See here:
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Configuringscriptedalerts

The best option I think is via custom search commands. I am working on one that would hand over results from Splunk search into posteifmsg. I think that's what you are looking for (Should be working ok with nco_postmsg as well) ...
search would be like
index=xyz OnCallGroup=*|rename source AS AlertKey|table OnCallGroup AlertKey _time|posteifmsg

Thing is: I am somewhat new to python so it'll take some time I think. I will post it to splunkbase once finished.

View solution in original post

hgehrts_splunk
Splunk Employee
Splunk Employee

Hi

You can send some of the information into an alert action but not the results from the query. See here:
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Configuringscriptedalerts

The best option I think is via custom search commands. I am working on one that would hand over results from Splunk search into posteifmsg. I think that's what you are looking for (Should be working ok with nco_postmsg as well) ...
search would be like
index=xyz OnCallGroup=*|rename source AS AlertKey|table OnCallGroup AlertKey _time|posteifmsg

Thing is: I am somewhat new to python so it'll take some time I think. I will post it to splunkbase once finished.

larryleeroberts
Path Finder

That is EXACTLY what I would be after 🙂
I see, so you are finding the OnCallGroup information from a lookup table in Splunk. Correct?

Good info! Yes, please keep me posted on your progress as I would be very interested in this once you have it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...