Alerting

How do you set alert severity?

sillingworth
Path Finder

I've created a custom alert action and I want to include alert severity as one of its parameters, with a user Interface (UI) element to select it. So far I have found two solutions, neither of which is exactly what I want.

Solution 1 is to simply have my own parameter, let's call it my_severity, which is totally independent of anything else. This works, but it means if you have other actions triggered on the same alert you can have multiple severity settings to manage.

Solution 2 is to use alert.severity, which can be set by including the "Add to Triggered Alerts" action in your alert, and using the drop down menu in that alert to set the severity. This also isn't ideal as it means you can't use my custom alert action on its own.

Is it possible to replicate the alert severity drop-down menu in my own action's UI, so that both are based on the same parameter?

Tags (2)

jfaldmomacu
Path Finder

Did you ever find a solution to this?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...