All Apps and Add-ons

Where can I set the app context in the Incident Settings on the Alert Manager 2.0 app with Splunk 6.3?

Plotkowski
Path Finder

Hi,

Where can I set the App context in the incident settings on Alert Manager 2.0 with Splunk 6.3?

I can only see the alarms from the Search app, not from other apps like DMC. and there is no option to change the app context.

Tags (2)
0 Karma
1 Solution

Simon
Contributor

Hi
The context doesn't need to be selected explicitly anymore. In the incident settings, alarms get listed with the following criteria from all apps whether it's sharing is app only or global:

  • The Custom Alert Action is enabled
  • The alarm is not private

Can you double-check if your alarm meets the criteria above?
Thanks,
Simon

View solution in original post

0 Karma

Simon
Contributor

Hi
The context doesn't need to be selected explicitly anymore. In the incident settings, alarms get listed with the following criteria from all apps whether it's sharing is app only or global:

  • The Custom Alert Action is enabled
  • The alarm is not private

Can you double-check if your alarm meets the criteria above?
Thanks,
Simon

0 Karma

Plotkowski
Path Finder

Thank you that was the problem. After upgrading we still had only the script-action under "actions" and not the custom alert action. After we enabled it in the actions the alarm showed up under incident settings.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...