Dashboards & Visualizations

Unable to get incidents loaded in the Alert Manager's Incident Posture

shiv1593
Communicator

Hi All,

We're using Alert Manager as a solution to produce Incidents, just like the Incident review dashboard in the Enterprise Security Suite. We have followed all the instructions given in the document, yet are not able to display incidents in the Posture.

  1. We installed the app and the add-on on the search head
  2. Created an index called alerts
  3. Set the alerts in the Alert manager app. Assigned the default roles created by the app to the users using it.
  4. Changed the permissions of the all the alerts and macros, even the Posture dashboard to Global.

We're getting the data in the dashboard metrics, as visible in the screenshot. But the incidents are still not displaying. Can anyone help us in setting this. Also, do we really need to install the add on each of our Indexers as well? Will that solve the problem?

alt text

Thanks in advance

0 Karma
1 Solution

shiv1593
Communicator

Resolved it myself. The problem was like finding a needle in the haystack of sand in a desert. The search of the macro all_alerts had a field called result_ID. That wasn't producing any results. Removed it, updated and got the search working, updated the macro and boom. Results popped up in the dashboard.

Helpful tips for the app:

  1. Make your Incident posture dashboard's permissions setting to global, also do the same for your macros.
  2. Look for any errors in the data model, or the predefined searches of the macros.
  3. If you didn't make the index with the default name "alerts", make sure to update it in the app as well as in the macro.
  4. To get rid of the socket errors, consider increasing the ulimits of your search head and the self imposed limits of the REST API in the server.conf file.

View solution in original post

0 Karma

shiv1593
Communicator

Resolved it myself. The problem was like finding a needle in the haystack of sand in a desert. The search of the macro all_alerts had a field called result_ID. That wasn't producing any results. Removed it, updated and got the search working, updated the macro and boom. Results popped up in the dashboard.

Helpful tips for the app:

  1. Make your Incident posture dashboard's permissions setting to global, also do the same for your macros.
  2. Look for any errors in the data model, or the predefined searches of the macros.
  3. If you didn't make the index with the default name "alerts", make sure to update it in the app as well as in the macro.
  4. To get rid of the socket errors, consider increasing the ulimits of your search head and the self imposed limits of the REST API in the server.conf file.
0 Karma

Ina
New Member

Thank you @shiv1593 

This post helped me to fix the same issue I had.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...