All Apps and Add-ons

TA-ivanti-ism: URL parameters for unfiltered ingestion of incidents

misner
New Member

Hello -

Is there a recommended URL parameter to use in the TA for Ivanti Service Manager (TA-ivanti-ism) to essentially ingest all Incidents data?

The default is %24filter%3DStatus%20eq%20%27Active%27%20or%20Status%20eq%20%27Logged%27 which resolves to $filter=Status eq 'Active' or Status eq 'Logged'.

We attempted %24filter%3DStatus%20eq%20%27*%27 which resolves to $filter=Status eq '*', but this was not successful in bringing in data.

Simply leaving the URL parameter blank also was unsuccessful in returning any data.

Thanks for your help.

0 Karma

jme147
Engager

Did you ever get this working? I am running into the same issue.

I thought i could just login to the ISM and go to the Incident workspace and select the search i wanted to pull from "All Active Incidents" (i.e. http://ism_url/heat/Default.aspx#1622727356175).

I don't think this is working because i don't see any data in my index yet.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...