All Apps and Add-ons

how to create custom statuses and workflow rules?

marcoscala
Builder

Hi!
I tired Alert Manager recently and I think it's a great app!

Now I need to customize the statuses and provide some simple workflow defining rules on who can change from a status to another one.

Any ideas or anyone already did it?

Thanks a lot!
Marco

my2ndhead
SplunkTrust
SplunkTrust

Support has been added to 2.2 and the next release will incorporate some additional improvements e.g. https://github.com/simcen/alert_manager/issues/213

0 Karma

jkat54
SplunkTrust
SplunkTrust

there is a lookup file called alert_status.csv, have you tried editing it and restarting?

You can find it in the lookups folder in the app.

0 Karma

marcoscala
Builder

Hi,Thanks!
I saw it and changed status descriptions. But I need a way to define status transitions based on roles.

Marco

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...