Splunk Enterprise Security

Splunk Enterprise Security / OpsGenie integration issue

AlexeySh
Communicator

Hello,

I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.X) and/or last version of Splunk Enterprise Security (5.2.X).

We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed OpsGenie Splunk app, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:

  • In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.

  • In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.

Do you have any advice?

Thanks for the help.

Alex.

0 Karma

dzayas
Explorer

Alexey, did you ever figure this out? We just implemented OpsGenie too. None of my existing correlation searches have the options of apply the OpsGenie trigger action in ES. However, I can see the OpsGenie trigger action in the Search and Reporting app alerts.

0 Karma

AlexeySh
Communicator

Hi @dzayas ,

Unfortunately, it's impossible to integrate ES correlation searches with OpsGenie app (or at least it was back in May 2019). Correlation Search is not the same type of instances as a Search Alert in Splunk, and after checking with OpsGenie support we've found that nothing's happen on OpsGenie side when a Correlation Search is triggered.

The workaround we finally used was to synchronise Splunk ES Notable Events and OpsGenie alerts via email. For each Splunk ES Notable Event we added a "Send Email" response action and added an OpsGenie email as a recipient. Then in OpsGenie we set up an alert creation for each Notable Event based on Sender and Email Title (unique for each Notable Event).

Unfortunately, in this case you loose some of ES capabilities, like flexible alert Urgency (based on Notable Event urgency and asset's urgency). Instead you have to select a fixed urgency for each alert in OpsGenie. But it's better than nothing

Hope it was helpful 🙂

0 Karma

dzayas
Explorer

It's definitely helpful!

Looks like that it's definitely the case where OpsGenie and ES don't work together. I took a look at the internal logs and when the correlation searches invoke the opsgenie app, it fails:

ERROR sendmodalert - Error in 'sendalert' command: Alert action "opsgenie" not found.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!