Splunk Enterprise Security

Splunk Enterprise Security / OpsGenie integration issue

AlexeySh
Communicator

Hello,

I’d like to know if anyone was able to integrate OpsGenie with the last versions of Splunk (7.2.X) and/or last version of Splunk Enterprise Security (5.2.X).

We use Splunk 7.2.5 and Splunk Enterprise Security 5.2.2 and we’d like to automatically create an alert in OpsGenie whenever an alert is created in Splunk ES. We've installed OpsGenie Splunk app, but it looks pretty obsolete (last version published Oct. 31, 2017) and doesn’t seem to work correctly:

  • In Splunk you can add OpsGenie as a response action, but you can’t manage any detail, like alert priority, etc.

  • In Splunk Enterprise Security there is no OpsGenie action in the response action list at all.

Do you have any advice?

Thanks for the help.

Alex.

0 Karma

dzayas
Explorer

Alexey, did you ever figure this out? We just implemented OpsGenie too. None of my existing correlation searches have the options of apply the OpsGenie trigger action in ES. However, I can see the OpsGenie trigger action in the Search and Reporting app alerts.

0 Karma

AlexeySh
Communicator

Hi @dzayas ,

Unfortunately, it's impossible to integrate ES correlation searches with OpsGenie app (or at least it was back in May 2019). Correlation Search is not the same type of instances as a Search Alert in Splunk, and after checking with OpsGenie support we've found that nothing's happen on OpsGenie side when a Correlation Search is triggered.

The workaround we finally used was to synchronise Splunk ES Notable Events and OpsGenie alerts via email. For each Splunk ES Notable Event we added a "Send Email" response action and added an OpsGenie email as a recipient. Then in OpsGenie we set up an alert creation for each Notable Event based on Sender and Email Title (unique for each Notable Event).

Unfortunately, in this case you loose some of ES capabilities, like flexible alert Urgency (based on Notable Event urgency and asset's urgency). Instead you have to select a fixed urgency for each alert in OpsGenie. But it's better than nothing

Hope it was helpful 🙂

0 Karma

dzayas
Explorer

It's definitely helpful!

Looks like that it's definitely the case where OpsGenie and ES don't work together. I took a look at the internal logs and when the correlation searches invoke the opsgenie app, it fails:

ERROR sendmodalert - Error in 'sendalert' command: Alert action "opsgenie" not found.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...