Splunk Enterprise Security

Splunk Enterprise Security / OpsGenie integration issue

AlexeySh
Communicator

Hello,

I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.X) and/or last version of Splunk Enterprise Security (5.2.X).

We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed OpsGenie Splunk app, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:

  • In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.

  • In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.

Do you have any advice?

Thanks for the help.

Alex.

0 Karma

dzayas
Explorer

Alexey, did you ever figure this out? We just implemented OpsGenie too. None of my existing correlation searches have the options of apply the OpsGenie trigger action in ES. However, I can see the OpsGenie trigger action in the Search and Reporting app alerts.

0 Karma

AlexeySh
Communicator

Hi @dzayas ,

Unfortunately, it's impossible to integrate ES correlation searches with OpsGenie app (or at least it was back in May 2019). Correlation Search is not the same type of instances as a Search Alert in Splunk, and after checking with OpsGenie support we've found that nothing's happen on OpsGenie side when a Correlation Search is triggered.

The workaround we finally used was to synchronise Splunk ES Notable Events and OpsGenie alerts via email. For each Splunk ES Notable Event we added a "Send Email" response action and added an OpsGenie email as a recipient. Then in OpsGenie we set up an alert creation for each Notable Event based on Sender and Email Title (unique for each Notable Event).

Unfortunately, in this case you loose some of ES capabilities, like flexible alert Urgency (based on Notable Event urgency and asset's urgency). Instead you have to select a fixed urgency for each alert in OpsGenie. But it's better than nothing

Hope it was helpful 🙂

0 Karma

dzayas
Explorer

It's definitely helpful!

Looks like that it's definitely the case where OpsGenie and ES don't work together. I took a look at the internal logs and when the correlation searches invoke the opsgenie app, it fails:

ERROR sendmodalert - Error in 'sendalert' command: Alert action "opsgenie" not found.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...