Alerting

Splunk alert results link invalid after some times for alerts on OpsGenie integration

ivanalmendros
New Member

I have an integration between Opsgenie and Splunk in order to create Opsgenie alerts whenever some Splunk alerts are created.
The thing is I've been having some issues with one of the dynamic properties available for such integration, the {{results_link}}.

This link is such a useful asset since it allows devs to be forwarded to the specific search that raised the alert in Splunk. However, we've been seeing some weird behaviour with these results link.
For some reason, they seem to stop working at some point. Here's an example of an alert that was generated in Splunk and hence created an alert in Opsgenie through the integration, which had a field with the {{results_link}} property added.

The following screenshots are for the exact same link at different times (yesterday afternoon and this morning) where you can see it was a valid query and then it isn't.

 

Screenshot 2024-06-19 at 12.25.14.pngScreenshot 2024-06-19 at 12.38.52.png

  


We need help understanding why this link stops working at some point and how could we avoid that behaviour.

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...