Alerting

Where do you package your alert_actions.conf for Splunk ES?

daniel333
Builder

All,

I know Splunk ES is a little picky about apps installed with it and created. I was going to create an app called mycompany_splunkes_base and toss in all my configs like server.conf and alert_actions.conf there. Any reason that would be a bad idea?

0 Karma

starcher
SplunkTrust
SplunkTrust

If you are making alert actions for ES use add on builder and make proper additive responses.

http://www.georgestarcher.com/splunk-slides-addon-builder-and-alert-actions/

Also name any apps like TA-myapp or SA-myapp so you don’t gave to edit the ES app filter to import it.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.