Splunk Enterprise

Ticket Creation in Jira from Splunk as an alert-action?

sarvesh_11
Communicator

Hello Splunkers,

https://splunkbase.splunk.com/app/5037/ i am using this add-on to create a ticket in Jira, as an alert action.

But after the set-up giving the JIRA URL and Credentials, it gives an error for this query:

index=_internal sourcetype=splunkd component=sendmodalert

sarvesh_11_0-1633948731743.png

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, error 5 is "unexpected error" so hard to say what happened without detailed logs.

Did you do as the https://splunkbase.splunk.com/app/5037/#/details says in Troubleshooting section?

0 Karma

sarvesh_11
Communicator

yeah i did that. Doing Debug on sendmodalert, gave me 400 logs for 1alert. on checking that, everything looks fine, except these 4 events.

 

I just wanted to know about command "sendalert", where is this command?

As it shows in logs, "Error is sendalert command". I am unable to locate the python file for this command.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

sendalert seems to be a custom splunk command probably using some helper script.

Easiest way to find where it's defined is

find /path/to/the/app -type f -name \*.conf | xargs grep sendalert
0 Karma

sarvesh_11
Communicator

M clueless, how to proceed.

Any other way, we can do splunk jira integration? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What I'd try:

  1. Check logs on Jira's side to see whether there are more meaningful error messages there
  2. If possible - disable encryption or put some MITM proxy in place and check the raw HTTP communication between Splunk and Jira.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...