We create alerts with table results but when they send via the OPSGenie integration, we only see one row or its not cormatted as readable. Is there a way to solve this?
Hi @heidi.rechek
I have looked at our documentation and can see no indication that sending a table is included in the default functionality, could you please confirm if someone may have modified our plugin that is installed on your Splunk server?
Is the data from splunk to OpsGenie passed in json or a specific format?
Is there a way to make it possible to pass tabled results through the integration?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Sorry for the delay in response. Yes, the payload sent from Splunk to Opsgeie is JSON. If you are using Splunk Enterprise your admins will be able to access our Opsenie plugin, there is an opsgenie.py script that can be customized so customers can include additional functions to facilitate their use cases. Your admins/developers will need to construct a logic in Splunk to export the table to a file, the extend the before mentioned opsgenie.py to include a function that triggers the Add Alert Attachment API call.
2 things to note is the above is not possible using the Splunk Cloud, you need to be running your own hosted version of Splunk Enterprize server, lastly please note the Opsgenie Support only supports the default functionality of each integration, if you do not have admin/developers who can handle the task please refer to an Atlassian partner in your local region.
I hope this helps, thanks and kind regards,
Allen
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.