Splunk Enterprise

submit issue from splunk

indeed_2000
Motivator

Hi How can create issue (on demand) in my "issue tracker" from splunk?

e.g I search through the logs suddenly found two events that need work on it, then hit bottom on splunk it will automatcally create issue and attach that events to this issue on my issue tracker.

 

FYI: I know alert will be do this but alert is autmatic process I need on demand.

 

Any idea?

Thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it isn't so clear what you mean with " create issue (on demand) in my issue tracker from splunk".

Using Splunk, you can automatically open a ticket in your issue tracker when an alert is triggered, but I don't understan the feature using Splunk to open a ticket.

Anyway, you can put an html button in a dashboard that calls an API or a web service of your trackes.

You can eventually pass informations from a dashboard panel or a report or send a mail to your tracker.

Then, which is your issue tracker system? does it have APIs or web services?

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-like we save search, put button that create issue.

Is it possible to do this in search app? Without dashboard?

 

2-This is the issue tracker

https://www.jetbrains.com/help/youtrack/devportal/api-howto-create-issue.html

 

Any idea?

 Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it's difficoult to understand you basic requirement and more difficoult ro understan the requirement to open a case from search App.

Anyway, you can create a custom command in Python to use in a search.

You could create this command that call APIs to pass passes parameters (e.g. the results of a search9 to an external system.

You can find more infos at:

https://docs.splunk.com/Documentation/Splunk/8.2.1/Search/Aboutcustomsearchcommands

https://dev.splunk.com/enterprise/docs/devtools/customsearchcommands/

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...