Splunk ITSI

Getting link to the Splunk ITSI event/episode

abhi04
Communicator

Hi,

 

I am trying to form a custom link to the episode/event in the email alert triggered from SPlunk ITSI.

 

However, when I open the link to that event or episode directly it always opens the alert and episode link and you the have to again search for the events and check the details.

 

Is there a way to get the link to the episode directly taht a person can open without searching from the ist of the events?


 

the link to specific episode e.g. https://splunkcloud.com/en-US/app/itsi/itsi_event_management?tab=layout_1&emid=1sdfdff-3cd3-11f0-b7a...

when opened in separate window does not open that specific episode

the above url is modified to not share the exact url for the episode.

 

Labels (1)
0 Karma

srauhala_splunk
Splunk Employee
Splunk Employee

To extend @skramp answer. 

episodeid in the episode review url references the episode id that is stored as itsi_group_id in the itsi_grouped_alerts index. 

Below its an example of the Episode Review  link I would pass in an email from an alert rule in the NEAP 

https://itsi.<stack_name>.splunkcloud.com/en-GB/app/itsi/itsi_event_management?earliest=$result.itsi_first_event_time$&latest=$result.itsi_last_event_time$&episodeid=$result.itsi_group_id$&showsummarydashboard=false

 

/Seb

0 Karma

skramp
SplunkTrust
SplunkTrust

That's quite easy. Every Episode has an ID, so you can build a link like https://yoursplunkinstance/en-US/app/itsi/itsi_event_management?episodeid=abc25865-33b3-484b-bd45-5d... 

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...