Alerting

What is the difference between a custom alert action and a scripted alert action?

nagarjuna280
Communicator

What is the difference between a custom alert action and a scripted alert action? We use the script in both actions: why do we need to create an app for custom alert actions? Instead, we can just use a script to generate an alert.

Tags (3)
0 Karma
1 Solution

harsmarvania57
SplunkTrust
SplunkTrust

Hi @nagarjuna280,

Scripted Alert has been deprecated and it has been replaced with Custom Alert action so that's why it will be good to migrate from Scripted Alert to Custom Alert actions.

With custom alert actions you can pass different values which are not present in Splunk query output but it is require to run the script this is one of the advantage and custom alert actions runs on different framework compared to scripted alert and due to that you need to create App for custom alert actions, which contains different configuration files, html file and script.

View solution in original post

harsmarvania57
SplunkTrust
SplunkTrust

Hi @nagarjuna280,

Scripted Alert has been deprecated and it has been replaced with Custom Alert action so that's why it will be good to migrate from Scripted Alert to Custom Alert actions.

With custom alert actions you can pass different values which are not present in Splunk query output but it is require to run the script this is one of the advantage and custom alert actions runs on different framework compared to scripted alert and due to that you need to create App for custom alert actions, which contains different configuration files, html file and script.

tom_frotscher
Builder

Hi,

you can of course just use the scripted alert action. The custom alert action is just more of a "framework concept".
For example, you have better integration in the UI, where you can configure parameters for the script. You can package the script as an app and share it via splunk base or in your environment. Those things just makes it more flexible. If you do not need this flexibility, you might have no need to use a custom alert action.

Greetings

Tom

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...