All Apps and Add-ons

There is no "set up" link in SplunkCloud app manager — how do I configure xMatters Actionable Alerts for Splunk without this?

nmclaughl1
Explorer

After installing on a search head I have filesystem-access to, I was pleased to discover I could configure xMatters credentials in Splunk's /manager UI and proceed to test & verify Saved Search -> Alert Action -> call xMatters -> receive Notifications.

After SplunkCloud Ops installed the same version in a maintenance window (SH requires restart), the link was not visible in the SplunkCloud /manager.

0 Karma
1 Solution

lakshman239
Influencer

In your dev/test instance, your configurations appear in $SPLUNK_HOME/etc/apps//local

You can create a custom app with local folder having similar config but with production details and ask splunk support to deploy it. It should work. [ you can test the same in in your dev, by creating the custom app having contents/configs of local folder].

I assume you have followed https://help.xmatters.com/integrations/logmgmt/splunk.htm?cshid=Splunk

View solution in original post

lakshman239
Influencer

In your dev/test instance, your configurations appear in $SPLUNK_HOME/etc/apps//local

You can create a custom app with local folder having similar config but with production details and ask splunk support to deploy it. It should work. [ you can test the same in in your dev, by creating the custom app having contents/configs of local folder].

I assume you have followed https://help.xmatters.com/integrations/logmgmt/splunk.htm?cshid=Splunk

nmclaughl1
Explorer

copied the URL from a non-prod, non-SplunkCloud instance and I was able to access the configuration properties for the splunkbase.splunk.com/app/2901/ App, xMatters Actionable Alerts for Splunk

https://localsplunk.domain.com/en-US/manager/xmatters_alert_action/apps/local/xmatters_alert_action/...
https://private.splunkcloud.com/en-US/manager/xmatters_alert_action/apps/local/xmatters_alert_action...

...didn't need the absent link in /manager afterall.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@nmclaughl1 If your problem is resolved, please accept an answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...