Splunk Search

How to integrate Splunk with a ticketing system so if something fails, an alert triggers a webservice or email to generate a ticket?

andybadera
Engager

I have an enterprise app that of course does a lot of things. When some of these things fail, we want to either call a webservice, or possibly send an email, that generates a ticket within the IT ticketing system. (The webservice is definitely available; we're verifying whether or not email input is enabled for us.)

Are OOTB Splunk searches & alerts flexible enough to handle sending a customized email on their own, or do I need to look at a Splunk app, or possibly even polling the Splunk REST API?

The idea would be:
1. Splunk parses a log event of some type or within a specified ID range.
2. Splunk, a Splunk app, or an external app sends an email to the ticketing system that includes the body of the event, and possibly other details.

0 Karma
1 Solution

AndySplunks
Communicator

OOTB Splunk searches should be able to handle it.

I've had Splunk generate emails with content in the body of the email or attached as a CSV and then have HP Service Manager parse the data for a support request.

View solution in original post

AndySplunks
Communicator

OOTB Splunk searches should be able to handle it.

I've had Splunk generate emails with content in the body of the email or attached as a CSV and then have HP Service Manager parse the data for a support request.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...