All Apps and Add-ons

how to create custom statuses and workflow rules?

marcoscala
Builder

Hi!
I tired Alert Manager recently and I think it's a great app!

Now I need to customize the statuses and provide some simple workflow defining rules on who can change from a status to another one.

Any ideas or anyone already did it?

Thanks a lot!
Marco

my2ndhead
SplunkTrust
SplunkTrust

Support has been added to 2.2 and the next release will incorporate some additional improvements e.g. https://github.com/simcen/alert_manager/issues/213

0 Karma

jkat54
SplunkTrust
SplunkTrust

there is a lookup file called alert_status.csv, have you tried editing it and restarting?

You can find it in the lookups folder in the app.

0 Karma

marcoscala
Builder

Hi,Thanks!
I saw it and changed status descriptions. But I need a way to define status transitions based on roles.

Marco

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...