Alerting

How do you set alert severity?

sillingworth
Path Finder

I've created a custom alert action and I want to include alert severity as one of its parameters, with a user Interface (UI) element to select it. So far I have found two solutions, neither of which is exactly what I want.

Solution 1 is to simply have my own parameter, let's call it my_severity, which is totally independent of anything else. This works, but it means if you have other actions triggered on the same alert you can have multiple severity settings to manage.

Solution 2 is to use alert.severity, which can be set by including the "Add to Triggered Alerts" action in your alert, and using the drop down menu in that alert to set the severity. This also isn't ideal as it means you can't use my custom alert action on its own.

Is it possible to replicate the alert severity drop-down menu in my own action's UI, so that both are based on the same parameter?

Tags (2)

jfaldmomacu
Path Finder

Did you ever find a solution to this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...