Archive
Highlighted

Where do you package your alert_actions.conf for Splunk ES?

Builder

All,

I know Splunk ES is a little picky about apps installed with it and created. I was going to create an app called mycompanysplunkesbase and toss in all my configs like server.conf and alert_actions.conf there. Any reason that would be a bad idea?

0 Karma
Highlighted

Re: Where do you package your alert_actions.conf for Splunk ES?

SplunkTrust
SplunkTrust

If you are making alert actions for ES use add on builder and make proper additive responses.

http://www.georgestarcher.com/splunk-slides-addon-builder-and-alert-actions/

Also name any apps like TA-myapp or SA-myapp so you don’t gave to edit the ES app filter to import it.

0 Karma