Hello,
I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.X) and/or last version of Splunk Enterprise Security (5.2.X).
We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed OpsGenie Splunk app, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:
In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.
In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.
Do you have any advice?
Thanks for the help.
Alex.
Alexey, did you ever figure this out? We just implemented OpsGenie too. None of my existing correlation searches have the options of apply the OpsGenie trigger action in ES. However, I can see the OpsGenie trigger action in the Search and Reporting app alerts.
Hi @dzayas ,
Unfortunately, it's impossible to integrate ES correlation searches with OpsGenie app (or at least it was back in May 2019). Correlation Search is not the same type of instances as a Search Alert in Splunk, and after checking with OpsGenie support we've found that nothing's happen on OpsGenie side when a Correlation Search is triggered.
The workaround we finally used was to synchronise Splunk ES Notable Events and OpsGenie alerts via email. For each Splunk ES Notable Event we added a "Send Email" response action and added an OpsGenie email as a recipient. Then in OpsGenie we set up an alert creation for each Notable Event based on Sender and Email Title (unique for each Notable Event).
Unfortunately, in this case you loose some of ES capabilities, like flexible alert Urgency (based on Notable Event urgency and asset's urgency). Instead you have to select a fixed urgency for each alert in OpsGenie. But it's better than nothing
Hope it was helpful 🙂
It's definitely helpful!
Looks like that it's definitely the case where OpsGenie and ES don't work together. I took a look at the internal logs and when the correlation searches invoke the opsgenie app, it fails:
ERROR sendmodalert - Error in 'sendalert' command: Alert action "opsgenie" not found.