Alerting

Help with custom alert action needed

damucka
Builder

Hello,

i would like to create the custom alert action attached to my alert. Whenever the alert brings back results (in my case: anomaly has been detected), then the dbxquery should be fired back against the DB generating there the runtime dump. No fancy UIs, simplest possible.

The rtedump creation is a procedure call on DB side, which at splunk would translate to sth. like that:

| dbxquery query="call \"SYS.MANAGEMENT_CONSOLE_PROC('runtimedump dump','$result.host_port$',?)" connection=$result.connection$

result.host_port and result.connection would / should be taken over from the alert search, there i would set it correspondingly.
Now, how would I do this in a simplest possible way? Do I need the [custom_alert_action].html also in this case? Where would I place all the necessary files / above search / parameters?

Kind Regards,
Kamil

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...