Splunk IT Service Intelligence

Is it possible to update alerts once custom action executed ?

jmarcoui2
Observer

Hi,

Really new to ITSI.

Already installed Splunk and ITSI on my customer site and read a lot of documentation.

I created a custom alert action (alert_action.conf and notable_alert_action.conf, don't remember exactly) in order to create a ticket to an external ticketing system accepting REST calls.

So also created a script in ../bin directory.

When I call the targeted ticketing system with REST POST, I get the INC number of the ticket created.

I would like to update the episode with this inc number in a specific field but didn't find similar situation here.

Can you help me ?

thank you in advance

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...