Splunk Enterprise

Ticket Creation in Jira from Splunk as an alert-action?

sarvesh_11
Communicator

Hello Splunkers,

https://splunkbase.splunk.com/app/5037/ i am using this add-on to create a ticket in Jira, as an alert action.

But after the set-up giving the JIRA URL and Credentials, it gives an error for this query:

index=_internal sourcetype=splunkd component=sendmodalert

sarvesh_11_0-1633948731743.png

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, error 5 is "unexpected error" so hard to say what happened without detailed logs.

Did you do as the https://splunkbase.splunk.com/app/5037/#/details says in Troubleshooting section?

0 Karma

sarvesh_11
Communicator

yeah i did that. Doing Debug on sendmodalert, gave me 400 logs for 1alert. on checking that, everything looks fine, except these 4 events.

 

I just wanted to know about command "sendalert", where is this command?

As it shows in logs, "Error is sendalert command". I am unable to locate the python file for this command.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

sendalert seems to be a custom splunk command probably using some helper script.

Easiest way to find where it's defined is

find /path/to/the/app -type f -name \*.conf | xargs grep sendalert
0 Karma

sarvesh_11
Communicator

M clueless, how to proceed.

Any other way, we can do splunk jira integration? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What I'd try:

  1. Check logs on Jira's side to see whether there are more meaningful error messages there
  2. If possible - disable encryption or put some MITM proxy in place and check the raw HTTP communication between Splunk and Jira.
0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...