Alerting

Recieve pop up alert on remote machine

j666gak
Communicator

Hello,

Is there a way of configuring so that when an alert occurs that a pop-up on a remote machine with a specified IP or IP range preferably by HTML or i guess NET SEND

The other nice to have would be if you have Enterprise Security Suite and configure in some way so that when an alert triggers it sets of an actual alarm bell or alarm light

Tags (2)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

You can have an alert run a script when firing. That alert script can do anything you can imagine.

  • A net send,
  • use a VOIP bridge to call a phone ( A good spot to plug http://pagerduty.com )
  • set off a (physical) alarm connected to a machine via some simple hardware (say a serial port's DTR)
  • A scrolling message board

Because you're writing the code that does the interfacing with whatever, the only limit is what you're willing to write. Splunk will, on the occurrence of an alert, call your script to do its magick.

View solution in original post

j666gak
Communicator

Thats great, thanks for the input, I shall try and see how I get on with a USB relay and a stroble light.

Thanks

0 Karma

dwaddle
SplunkTrust
SplunkTrust

You can have an alert run a script when firing. That alert script can do anything you can imagine.

  • A net send,
  • use a VOIP bridge to call a phone ( A good spot to plug http://pagerduty.com )
  • set off a (physical) alarm connected to a machine via some simple hardware (say a serial port's DTR)
  • A scrolling message board

Because you're writing the code that does the interfacing with whatever, the only limit is what you're willing to write. Splunk will, on the occurrence of an alert, call your script to do its magick.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...