All Apps and Add-ons

Can SCOM 2012 Notification Channels be built to inject subscription alerts into Splunk?

rhendle
Observer

New to Splunk and recently set up a test environment.....

Is it possible to use a SCOM command line channel using a script (not email) to inject alerts into an event management tool (not Splunk)?

  • Our current script uses variables to populate the alert info into the event management tool.
  • We have tons of custom subscriptions in SCOM that target a management pack classes but use a common the channel to inject into the event management tool.
  • I'm looking to migrate to Splunk and was wondering if anyone has built a channel to inject alerts into Splunk in a similar way or understand how you may be routing alerts by management pack class vs. build custom alert rules in Splunk.

Interested in hearing how others might be using SCOM Channels/Subscriptions into Splunk!!
Thank you!

0 Karma

rhendle
Observer

FYI - Resolved this issue by using powershell to inject event into HEC (HTTP Event Collector)

0 Karma

rhendle
Observer

FYI - I ended up figuring this out. Not sure if there is any interest but happy to document an example if there is anyone else trying to figure it out!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...