Splunk On-Call

Step through all members of a rotation

Gattaca2
Explorer

Hi

New to Splunk On-Call , I have setup a new Team with 3 members, and I've created a rotation and shift with all three as members.

I'm stuck with the best way to setup the Escalation Policy, I want it to call the initial person on call and then contact the other two in turn if they don't respond e.g.

Contact Member 1

Wait 10mins

Contact Member 2

Wait 10mins

Contact Member 3

 

They way I have it at the moment is having three steps in the Escalation Policy:

Step 1 - Immediate - Notify the On-Duty user(s) in rotation

Step 2 - Wait 10 mins - Notify the next user(s) in the current on-duty shift

Step 2 - Wait 20 mins - Notify the next user(s) in the current on-duty shift

 

Is this the best way to do it, the text "Notify the On-Duty user(s) in rotation" has confused me as it suggests that it should call multiple members in a rotation, but I can't find anything that describes how it calls more then the initial on-call person?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...