Alerting

How do you set alert severity?

sillingworth
Path Finder

I've created a custom alert action and I want to include alert severity as one of its parameters, with a user Interface (UI) element to select it. So far I have found two solutions, neither of which is exactly what I want.

Solution 1 is to simply have my own parameter, let's call it my_severity, which is totally independent of anything else. This works, but it means if you have other actions triggered on the same alert you can have multiple severity settings to manage.

Solution 2 is to use alert.severity, which can be set by including the "Add to Triggered Alerts" action in your alert, and using the drop down menu in that alert to set the severity. This also isn't ideal as it means you can't use my custom alert action on its own.

Is it possible to replicate the alert severity drop-down menu in my own action's UI, so that both are based on the same parameter?

Tags (2)

jfaldmomacu
Path Finder

Did you ever find a solution to this?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...