Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,298,477
Community Members
 
Community Events
165
Community Groups

Using Splunk integration, how do I reset or close an alert?

When a splunk alert fires, Opsgenie action is triggered and an alert is created in Opsgenie. 

I would like a second splunk alert to close the previously open alert in Opsgenie when it fires. How can that be done?

For example one Splunk search detects website is down, and a second one detects website is UP.

 

Thanks!

 

1 answer

0 votes

Hi @Mohamed Lrhazi ,

Using the advanced settings of the integration will empower you to fully customize your alerting. You can define when the system should create an alert, when it should execute a close action, acknowledge an alert automatically or add a note.

For example - the Create Alert action could create an alert when the Splunk search detects a website is DOWN, while the Close Alert action could close that existing alert when the Splunk search detects a website is UP. 

Note: closing an open existing Opsgenie alert through the integration is dependent on the alias field (also known as the unique identifier). Whatever data / fields you parse in the Create Alert action should be consistent with your Close Alert action (along with all integration actions). What data parses in the alias can also be configured under the advanced settings of the integration.

splunkcomm1.jpg

 

I don't personally have a Splunk instance, but here's an example of how that might be configured through an Email Integration - the idea is the same:

splunkcomm2.jpgsplunkcomm3.jpg

splunkcomm4.jpgsplunkcomm5.jpg

 

^ "XYZ123" was extracted into the alias of this alert upon creation, and was also used to identify which Opsgenie alert to close through the integration. Hope this helps! Let me know if you have any other questions.

 

Additional helpful links:

String Processing

Regex

Thanks a lot @Nick H , but I don't think you are correct!

I tried what you describe, defining the create and close actions... It seems the client, the integration client, needs to send an actual close request... it needs to call the close_alert API endpoint....  The splunk integration script only calls the create alert endpoint.

 

I ended up creating my own splunk integration script to do this.

Like Nick H likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Site Admin
TAGS
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

188 views 1 3
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you