- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to create tickets to an external ticketing system for incidents from Incident Review of Splunk Enterprise Security
ben2abraham
New Member
10-27-2015
03:18 AM
Team,
I know how to create tickets to an external ticketing system for single rules, but in Enterprise Security, it is difficult to go to all rules and modify output actions to run a script for creating tickets. Is there any way that I can follow so that I can see all the incidents in my external ticketing system at the same time when an incident is triggered in Incident view panel of Enterprise security rather than modifying rules one by one?
Regards,
Ben
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

smoir_splunk

Splunk Employee
11-14-2016
01:29 PM
@ben2abraham, you've probably solved this by now but all notable events that appear on the incident review dashboard populate a notable index that you could then read to send over to the ticketing system, rather than modifying the searches that create the notable events.
