Splunk Enterprise Security

How to create tickets to an external ticketing system for incidents from Incident Review of Splunk Enterprise Security

ben2abraham
New Member

Team,

I know how to create tickets to an external ticketing system for single rules, but in Enterprise Security, it is difficult to go to all rules and modify output actions to run a script for creating tickets. Is there any way that I can follow so that I can see all the incidents in my external ticketing system at the same time when an incident is triggered in Incident view panel of Enterprise security rather than modifying rules one by one?

Regards,
Ben

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

@ben2abraham, you've probably solved this by now but all notable events that appear on the incident review dashboard populate a notable index that you could then read to send over to the ticketing system, rather than modifying the searches that create the notable events.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...