Splunk Enterprise

Ticket Creation in Jira from Splunk as an alert-action?

sarvesh_11
Communicator

Hello Splunkers,

https://splunkbase.splunk.com/app/5037/ i am using this add-on to create a ticket in Jira, as an alert action.

But after the set-up giving the JIRA URL and Credentials, it gives an error for this query:

index=_internal sourcetype=splunkd component=sendmodalert

sarvesh_11_0-1633948731743.png

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, error 5 is "unexpected error" so hard to say what happened without detailed logs.

Did you do as the https://splunkbase.splunk.com/app/5037/#/details says in Troubleshooting section?

0 Karma

sarvesh_11
Communicator

yeah i did that. Doing Debug on sendmodalert, gave me 400 logs for 1alert. on checking that, everything looks fine, except these 4 events.

 

I just wanted to know about command "sendalert", where is this command?

As it shows in logs, "Error is sendalert command". I am unable to locate the python file for this command.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

sendalert seems to be a custom splunk command probably using some helper script.

Easiest way to find where it's defined is

find /path/to/the/app -type f -name \*.conf | xargs grep sendalert
0 Karma

sarvesh_11
Communicator

M clueless, how to proceed.

Any other way, we can do splunk jira integration? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What I'd try:

  1. Check logs on Jira's side to see whether there are more meaningful error messages there
  2. If possible - disable encryption or put some MITM proxy in place and check the raw HTTP communication between Splunk and Jira.
0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...