Alerting

How to move alerts through a workflow

antb
Path Finder

Alarms at first glance, seem a bit limited but I may be missing something. Tried reading the docs and searching around in the community but haven't had luck today.

I can create them with severity (this is good), have them show in my "triggered alerts" but I cannot find workflow abilities… Choices like "annotate, assign, or close them (aside from delete)".

As an example a team would watch a board for an alert and would call-out to a response team. The team that is on-call or actioning should be able to remove the alerts from the other screen or assign them to individuals to work on (mark as in-progress).

I've done this in other SIEM's and hope it doesn't require webhooks to an external application, perhaps I can custom do this on a dashboard but would need a bit of guidance.

Thoughts? Thank you in advance. (First time posting)

0 Karma
1 Solution

tom_frotscher
Builder

Hi,

this is a feature that pretty much describes workflow handling in splunk enterprise security, which is a splunk premium solution. You can find more information and the posibility to get a demo here: https://www.splunk.com/en_us/software/enterprise-security.html

There is also a more light weight solution to this at splunk base, called alert manager:
https://splunkbase.splunk.com/app/2665/

Which seems to realize your mentioned use cases pretty accurate.

Greetings

Tom

View solution in original post

woodcock
Esteemed Legend

There is no case-management capability in core splunk. This featureset exists in Splunk's premium app Enterprise Security and also in the free Alert Manager app in splunkbase. We are also working on our own premium app for this (as are others, I am sure).

0 Karma

tom_frotscher
Builder

Hi,

this is a feature that pretty much describes workflow handling in splunk enterprise security, which is a splunk premium solution. You can find more information and the posibility to get a demo here: https://www.splunk.com/en_us/software/enterprise-security.html

There is also a more light weight solution to this at splunk base, called alert manager:
https://splunkbase.splunk.com/app/2665/

Which seems to realize your mentioned use cases pretty accurate.

Greetings

Tom

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...