Alerting

How do you set alert severity?

sillingworth
Path Finder

I've created a custom alert action and I want to include alert severity as one of its parameters, with a user Interface (UI) element to select it. So far I have found two solutions, neither of which is exactly what I want.

Solution 1 is to simply have my own parameter, let's call it my_severity, which is totally independent of anything else. This works, but it means if you have other actions triggered on the same alert you can have multiple severity settings to manage.

Solution 2 is to use alert.severity, which can be set by including the "Add to Triggered Alerts" action in your alert, and using the drop down menu in that alert to set the severity. This also isn't ideal as it means you can't use my custom alert action on its own.

Is it possible to replicate the alert severity drop-down menu in my own action's UI, so that both are based on the same parameter?

Tags (2)

jfaldmomacu
Path Finder

Did you ever find a solution to this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...