All Apps and Add-ons

splunk add on for Remedy - Incident triggered for Alerts capture Issue

Sasivarnan1234
Explorer

Hi,

I have created an alert and used splunk add on for Remedy to trigger incidents. Since I made few changes to API used based on our Remedy API the incidents are getting created but still in Splunk it shows "There are no fired events for this alert". May I know how this fired events are captured in splunk add on for remedy for alerts.

Thanks

Tags (1)
0 Karma

Sasivarnan1234
Explorer

Hi,

Could any one help here please? Much appreciated!

Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Sasivarnan,

Please note the following documented as a prerequisite on the Remedy side : http://docs.splunk.com/Documentation/AddOns/released/Remedy/Hardwareandsoftwarerequirements

For triggered alerts to successfully create new incidents for configuration items, you must configure incident rules and set the Consolidate Incidents option to No in BMC Remedy IT Service Management (ITSM). For information about configuring the Consolidate Incidents setting in the Remedy, refer to the related Remedy documentation:
https://docs.bmc.com/docs/display/public/BSR35/Consolidating+incidents

Hope this helps. Thanks!
Hunter

0 Karma

Sasivarnan1234
Explorer

Hi Hunter,

Thanks for your reply. Actually the issue here is I am able to create an incident successfully when the event occurs but when I navigate into the splunk remedy app and in alerts view I am seeing "There are no fired events for this alert". But already an incident has been triggered for the event but splunk not recognizing it.

Attached the snapshot for reference.

alt text
Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Also, make sure you have followed the instructions documented here:
http://docs.splunk.com/Documentation/AddOns/released/Remedy/Usecustomsearchcommands

Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...