All Apps and Add-ons

Alerts Manager app not showing any incidents or alerts from my ES environment

ezmo1982
Path Finder

Hi 

I installed the Alerts Manager app as I was hoping to have better features to view and manage my incidents and alerts in enterprise security. I installed the app (id:2665) and the add-on (id3665) to my SH, created a new index named alerts and completed the set up. 

However there are no Incidents or Alerts showing in any of the dashboards. My understanding was that this app would pull the incidents/alerts from ES so I can manage them? But nothing is showing

In the app, i can create a new incident no problem and can see it being added to the new "alerts" index, but this isn't much use to me.

Is there something im missing here regarding this app or its purpose??

Thanks

Labels (1)
0 Karma

jamesklassen
Path Finder

Hi there, did you get it working? I'm also having difficulties with this app.

0 Karma

ezmo1982
Path Finder

No, havnt got it working yet. Cant find a way for the app to display Enterprise Security alerts.

0 Karma

jamesklassen
Path Finder

So I fixed it in my environment. I incorrectly assumed that all existing alerts would get pulled in and listed automatically on the 'Incident Posture' dashboard. But, I needed to add the 'Alert Manager' action for my existing triggered alerts first; once that was done, then those alerts would show up. 

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...