Splunk Enterprise

submit issue from splunk

indeed_2000
Motivator

Hi How can create issue (on demand) in my "issue tracker" from splunk?

e.g I search through the logs suddenly found two events that need work on it, then hit bottom on splunk it will automatcally create issue and attach that events to this issue on my issue tracker.

 

FYI: I know alert will be do this but alert is autmatic process I need on demand.

 

Any idea?

Thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it isn't so clear what you mean with " create issue (on demand) in my issue tracker from splunk".

Using Splunk, you can automatically open a ticket in your issue tracker when an alert is triggered, but I don't understan the feature using Splunk to open a ticket.

Anyway, you can put an html button in a dashboard that calls an API or a web service of your trackes.

You can eventually pass informations from a dashboard panel or a report or send a mail to your tracker.

Then, which is your issue tracker system? does it have APIs or web services?

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-like we save search, put button that create issue.

Is it possible to do this in search app? Without dashboard?

 

2-This is the issue tracker

https://www.jetbrains.com/help/youtrack/devportal/api-howto-create-issue.html

 

Any idea?

 Thanks 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

it's difficoult to understand you basic requirement and more difficoult ro understan the requirement to open a case from search App.

Anyway, you can create a custom command in Python to use in a search.

You could create this command that call APIs to pass passes parameters (e.g. the results of a search9 to an external system.

You can find more infos at:

https://docs.splunk.com/Documentation/Splunk/8.2.1/Search/Aboutcustomsearchcommands

https://dev.splunk.com/enterprise/docs/devtools/customsearchcommands/

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...