Alerting

Modify session key expiration time custom script alert

mgarciar
Path Finder

Hi experts,

I have an alert that triggers a custom script (python), this script executes several validations on the data and creates a service using the passed session key to execute other 2 SPLs.
At some point the session key is expiring and script fails to execute SPLs.

I’m using the deprecated functionality for custom alerts.

Is there any way to increase the lifetime of the session key ?
Do I need to move to the new custom alert framework to avoid this issue?

I know I can move my code to a separate script that runs in a cron job outside splunk but then it’s more services to maintain plus having to use a username/password to create a splunk service.
The actual process is very convenient in that sense.

Thanks !

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...