Splunk IT Service Intelligence

Is it possible to update alerts once custom action executed ?

jmarcoui2
Observer

Hi,

Really new to ITSI.

Already installed Splunk and ITSI on my customer site and read a lot of documentation.

I created a custom alert action (alert_action.conf and notable_alert_action.conf, don't remember exactly) in order to create a ticket to an external ticketing system accepting REST calls.

So also created a script in ../bin directory.

When I call the targeted ticketing system with REST POST, I get the INC number of the ticket created.

I would like to update the episode with this inc number in a specific field but didn't find similar situation here.

Can you help me ?

thank you in advance

Labels (1)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...