All Apps and Add-ons

Alerts Manager app not showing any incidents or alerts from my ES environment

ezmo1982
Path Finder

Hi 

I installed the Alerts Manager app as I was hoping to have better features to view and manage my incidents and alerts in enterprise security. I installed the app (id:2665) and the add-on (id3665) to my SH, created a new index named alerts and completed the set up. 

However there are no Incidents or Alerts showing in any of the dashboards. My understanding was that this app would pull the incidents/alerts from ES so I can manage them? But nothing is showing

In the app, i can create a new incident no problem and can see it being added to the new "alerts" index, but this isn't much use to me.

Is there something im missing here regarding this app or its purpose??

Thanks

Labels (1)
0 Karma

jamesklassen
Path Finder

Hi there, did you get it working? I'm also having difficulties with this app.

0 Karma

ezmo1982
Path Finder

No, havnt got it working yet. Cant find a way for the app to display Enterprise Security alerts.

0 Karma

jamesklassen
Path Finder

So I fixed it in my environment. I incorrectly assumed that all existing alerts would get pulled in and listed automatically on the 'Incident Posture' dashboard. But, I needed to add the 'Alert Manager' action for my existing triggered alerts first; once that was done, then those alerts would show up. 

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...