#Random
This is a place to discuss all things outside of Splunk, its products, and its use cases.

Integrate Splunk Support portal tickets with on-prem Splunk

adalbor
Builder

Hey All,

Kind of an off the wall question here. Does anyone know of an API or a way to query our Splunk support portal accounts to pull ticket information? Would love to be able to create a dashboard on-prem detailing open tickets, then if possible pull open/close timestamps and overlay that onto a visualization showing potential event drops during the time span of the case being open.

Thanks,
Andrew

bhavikbhalodia
Path Finder

Hi @adalbor

You can create one python script which will fire Splunk Portal and Fetch All the required information from Splunk Portal and Send it to Splunk Using HEC or on any port. And this script will run at some defined interval.

Let me know for more information.

0 Karma

adalbor
Builder

Appreciate the info but that unfortunately only gives me a rough starting point. I wouldn't even know where to begin to fetch that info. Was hoping there was an API out there or something easier.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...