Splunk Search

How to integrate Splunk with a ticketing system so if something fails, an alert triggers a webservice or email to generate a ticket?

andybadera
Engager

I have an enterprise app that of course does a lot of things. When some of these things fail, we want to either call a webservice, or possibly send an email, that generates a ticket within the IT ticketing system. (The webservice is definitely available; we're verifying whether or not email input is enabled for us.)

Are OOTB Splunk searches & alerts flexible enough to handle sending a customized email on their own, or do I need to look at a Splunk app, or possibly even polling the Splunk REST API?

The idea would be:
1. Splunk parses a log event of some type or within a specified ID range.
2. Splunk, a Splunk app, or an external app sends an email to the ticketing system that includes the body of the event, and possibly other details.

0 Karma
1 Solution

AndySplunks
Communicator

OOTB Splunk searches should be able to handle it.

I've had Splunk generate emails with content in the body of the email or attached as a CSV and then have HP Service Manager parse the data for a support request.

View solution in original post

AndySplunks
Communicator

OOTB Splunk searches should be able to handle it.

I've had Splunk generate emails with content in the body of the email or attached as a CSV and then have HP Service Manager parse the data for a support request.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...