Splunk Enterprise

Not receiving auto cut

vishwa
Path Finder

I have bunch of alerts, I received email alert, but I did not receive auto cut incident to service now

How to troubleshoot this issue?????

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @vishwa ... 

Around when ServiceNow and Splunk integration was done? recent or long back?

the servicenow tickets auto cut(incident creation) was working fine previously

did you do any upgrades recently?(on SH, indexers, the apps, etc)

 

0 Karma

vishwa
Path Finder

Around when ServiceNow and Splunk integration was done? recent or long back?

Long back 

 

the servicenow tickets auto cut(incident creation) was working fine previously

Yes it was working fine 

did you do any upgrades recently?(on SH, indexers, the apps, etc)

No recent upgraded

0 Karma

inventsekar
SplunkTrust
SplunkTrust

are you not receiving Snow incident tickets only for a particular set of alerts 

or

are you not receiving Snow incident tickets for whole splunk altogether?

0 Karma

vishwa
Path Finder

I just tried for 4 to 5 alerts it not trigger yesterday

But again I tried today I am getting auto cuts now

Not sure what happened 

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

the apps/addons sometimes makes our lives difficult by doing like this. 

please check the internal logs for that servicenow app/addon... it may give you some hints, if you find the issue.. you can update this post, so in future other users can use your learnings.

 

karma / upvotes are appreciated by all. thanks. 

0 Karma

vishwa
Path Finder

There was some maintenance activity was there

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...