Alerting

Webhook payloads and the Enterprise REST API: How to retrieve the results of the alert that was triggered?

mv10
Path Finder

My webhook endpoint needs to retrieve the results of the alert that was triggered. Am I correct in thinking that the payload's "sid" value is the same as the Enterprise REST API's {search_id} value in the search/jobs/{search_id}/results endpoint?

I'm a little surprised the webhook docs don't say anything about this since it seems like the logical next step. Normally I'd just try it myself, but we're in a gigantic corporate environment, there's tons of paperwork to get permission to do anything, etc. etc. -- much faster to just ask if I'm on the right track. And, I guess, the other obvious question is, if I'm not on the right track, how do I retrieve the search results based on a webhook payload?

Thanks in advance!

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...