Alerting

How send splunk alerts to netcool?

romattos
New Member

How Can I send alerts from splunk to netcool ? The splunk is able to send alerts to netcool omnibus?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @romattos,
are yu speaking of IBM netcool?
Did you already explored the SNMP Splunk MA App for Netcool ( https://splunkbase.splunk.com/app/3596/ ) ?

otherwise it isn't so easy because, following the instructions at https://docs.splunk.com/Documentation/Splunk/6.2.1/alert/SendingSNMPtrapstoothersystems (as you can see it's old!), you have to create a perl script because in the 0 fields related to a fired alert you can find the url of a zipped files that contains the results of the search but you cannot send it to Netcool and you have to unzip it and add to one of the eight fields.

Ciao.
Giuseppe

0 Karma

romattos
New Member

Hi Giuseppe.

Yes . I want to send to IBM Netcool Omnibus. Is it possible? Do you have more details?

Thanks!!

0 Karma

hgehrts_splunk
Splunk Employee
Splunk Employee

Hi!
yes, it's possible. And there are several ways of doing this. The easiest might be
https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/AlertWorkflowOverview
where an alert action triggers a script that sends information into an Omnibus Probe.

best
Henning

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...