All Apps and Add-ons

splunk add on for Remedy - Incident triggered for Alerts capture Issue

Sasivarnan1234
Explorer

Hi,

I have created an alert and used splunk add on for Remedy to trigger incidents. Since I made few changes to API used based on our Remedy API the incidents are getting created but still in Splunk it shows "There are no fired events for this alert". May I know how this fired events are captured in splunk add on for remedy for alerts.

Thanks

Tags (1)
0 Karma

Sasivarnan1234
Explorer

Hi,

Could any one help here please? Much appreciated!

Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Sasivarnan,

Please note the following documented as a prerequisite on the Remedy side : http://docs.splunk.com/Documentation/AddOns/released/Remedy/Hardwareandsoftwarerequirements

For triggered alerts to successfully create new incidents for configuration items, you must configure incident rules and set the Consolidate Incidents option to No in BMC Remedy IT Service Management (ITSM). For information about configuring the Consolidate Incidents setting in the Remedy, refer to the related Remedy documentation:
https://docs.bmc.com/docs/display/public/BSR35/Consolidating+incidents

Hope this helps. Thanks!
Hunter

0 Karma

Sasivarnan1234
Explorer

Hi Hunter,

Thanks for your reply. Actually the issue here is I am able to create an incident successfully when the event occurs but when I navigate into the splunk remedy app and in alerts view I am seeing "There are no fired events for this alert". But already an incident has been triggered for the event but splunk not recognizing it.

Attached the snapshot for reference.

alt text
Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Also, make sure you have followed the instructions documented here:
http://docs.splunk.com/Documentation/AddOns/released/Remedy/Usecustomsearchcommands

Thanks!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...