Alerting

Help with custom alert action needed

damucka
Builder

Hello,

i would like to create the custom alert action attached to my alert. Whenever the alert brings back results (in my case: anomaly has been detected), then the dbxquery should be fired back against the DB generating there the runtime dump. No fancy UIs, simplest possible.

The rtedump creation is a procedure call on DB side, which at splunk would translate to sth. like that:

| dbxquery query="call \"SYS.MANAGEMENT_CONSOLE_PROC('runtimedump dump','$result.host_port$',?)" connection=$result.connection$

result.host_port and result.connection would / should be taken over from the alert search, there i would set it correspondingly.
Now, how would I do this in a simplest possible way? Do I need the [custom_alert_action].html also in this case? Where would I place all the necessary files / above search / parameters?

Kind Regards,
Kamil

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...