Splunk Enterprise

submit issue from splunk

indeed_2000
Motivator

Hi How can create issue (on demand) in my "issue tracker" from splunk?

e.g I search through the logs suddenly found two events that need work on it, then hit bottom on splunk it will automatcally create issue and attach that events to this issue on my issue tracker.

 

FYI: I know alert will be do this but alert is autmatic process I need on demand.

 

Any idea?

Thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it isn't so clear what you mean with " create issue (on demand) in my issue tracker from splunk".

Using Splunk, you can automatically open a ticket in your issue tracker when an alert is triggered, but I don't understan the feature using Splunk to open a ticket.

Anyway, you can put an html button in a dashboard that calls an API or a web service of your trackes.

You can eventually pass informations from a dashboard panel or a report or send a mail to your tracker.

Then, which is your issue tracker system? does it have APIs or web services?

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-like we save search, put button that create issue.

Is it possible to do this in search app? Without dashboard?

 

2-This is the issue tracker

https://www.jetbrains.com/help/youtrack/devportal/api-howto-create-issue.html

 

Any idea?

 Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it's difficoult to understand you basic requirement and more difficoult ro understan the requirement to open a case from search App.

Anyway, you can create a custom command in Python to use in a search.

You could create this command that call APIs to pass passes parameters (e.g. the results of a search9 to an external system.

You can find more infos at:

https://docs.splunk.com/Documentation/Splunk/8.2.1/Search/Aboutcustomsearchcommands

https://dev.splunk.com/enterprise/docs/devtools/customsearchcommands/

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...