Splunk IT Service Intelligence

Is it possible to update alerts once custom action executed ?

jmarcoui2
Observer

Hi,

Really new to ITSI.

Already installed Splunk and ITSI on my customer site and read a lot of documentation.

I created a custom alert action (alert_action.conf and notable_alert_action.conf, don't remember exactly) in order to create a ticket to an external ticketing system accepting REST calls.

So also created a script in ../bin directory.

When I call the targeted ticketing system with REST POST, I get the INC number of the ticket created.

I would like to update the episode with this inc number in a specific field but didn't find similar situation here.

Can you help me ?

thank you in advance

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...