We are trying to invoke alerts from Splunk to NetCool, and wondering what the right approach would be. We came up with 3 proposals -
Solution 1 : Create a script, and invoke in alert actions, and pass the parameters.
Solution 2 : Create a custom command, and append it to the SPL, and pass the arguments.
Solution 3: Create a custom alert action, with html form fields. (Just like Send Email/Snow) - Preferred
We also came across Splunk dev documentation at Create custom alert actions for Splunk Cloud Platform or Splunk Enterprise
Any feedback would be appreciated.
... View more