Alerting

How to show alerts as a pop up or toast?

pedram
Engager

We have a small dashboard and we would like to have a script alert action or a custom alert action.

What we would like to do is to send a toast or a pop up notification to the system so when the alert is triggered, if the operator is not looking at the dashboard, they will be able to see the pop up or toast in the bottom right corner of screen. Just like an alert you get from MS Outlook for a new email. 

Is this possible? Any help would be appreciated. 

Labels (1)
0 Karma
1 Solution

jacobpevans
Motivator

Greetings @pedram ,

See here: https://community.splunk.com/t5/Splunk-Search/How-to-display-a-popup-when-i-open-the-dashboard/m-p/5...

Long story short. Yes, it's possible. No, Splunk can not do it natively. If you want it, you have to build it.

However, for your use case, Splunk can natively publish custom messages to the Messages drop-down at the top-right of every screen. Here's the REST endpoint to manipulate it: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsystem#messages. It is accessible via GUI as Settings > User Interface > Bulletin Messages.

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.

View solution in original post

0 Karma

jacobpevans
Motivator

Greetings @pedram ,

See here: https://community.splunk.com/t5/Splunk-Search/How-to-display-a-popup-when-i-open-the-dashboard/m-p/5...

Long story short. Yes, it's possible. No, Splunk can not do it natively. If you want it, you have to build it.

However, for your use case, Splunk can natively publish custom messages to the Messages drop-down at the top-right of every screen. Here's the REST endpoint to manipulate it: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsystem#messages. It is accessible via GUI as Settings > User Interface > Bulletin Messages.

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

It’s go time — Boston, here we come!

Are you ready to take your Splunk skills to the next level? Get set, because Splunk University is back, and ...