Alerting

Where do you package your alert_actions.conf for Splunk ES?

daniel333
Builder

All,

I know Splunk ES is a little picky about apps installed with it and created. I was going to create an app called mycompany_splunkes_base and toss in all my configs like server.conf and alert_actions.conf there. Any reason that would be a bad idea?

0 Karma

starcher
Influencer

If you are making alert actions for ES use add on builder and make proper additive responses.

http://www.georgestarcher.com/splunk-slides-addon-builder-and-alert-actions/

Also name any apps like TA-myapp or SA-myapp so you don’t gave to edit the ES app filter to import it.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...