Disclaimer: I'm an employee at OpsGenie 🙂
OpsGenie's custom alert action retrieves the raw payload from the Splunk and parses your data to construct rich and informative alerts. You can use dynamic fields to customize alert properties, as well as alert conditions.
Regarding your question, we acquire the data using a similar method to Splunk's Webhook alert action. If you want to develop your own custom action, this document might be helpful:https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/AdvancedDev/CustomAlertConvertScripted
Detailed information could be found in our Splunk Integration:https://docs.opsgenie.com/docs/splunk-integration
Sincerely,
Bener
... View more