Integrations
Splunk
EvoHub receives Splunk alerts through the Webhook alert action. Each time an alert triggers, EvoHub opens an alert with the first result row. Splunk does not send a notification when the condition clears, so these alerts are resolved in EvoHub.
Set it up
Create the integration
In EvoHub, go to On-Call → Integrations → + Add Integration, choose Splunk, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.
Splunk's webhook body is read as it is:
{
"search_name": "Failed root logins",
"result": { "host": "web-07", "count": "8" },
"sid": "scheduler_admin_search_W2_at_14232356_132",
"results_link": "https://splunk.example.com/app/search/@go?sid=...",
"owner": "admin",
"app": "search"
}
What EvoHub reads
| EvoHub alert | Taken from |
|---|---|
| Title | search_name, plus " on host" when the result has a host field. |
| Description | The first result row as field: value lines (internal fields other than _raw are left out). |
| Labels | app, owner, host, sid, and url (the results_link). |
| Fingerprint | The search name, plus host when present. |
Severity
If the result row has a severity field, EvoHub uses it: critical, high, medium, low or info (error reads as high, warning as medium). Set it in the search, for example:
... | eval severity="critical"
Without one, Splunk alerts are high.
Resolve and deduplication
- Splunk sends no recovery notification. Resolve the alert in EvoHub when the problem is fixed.
- Each run of the same search for the same host, while the alert is open, is recorded as Retriggered. The search ID changes every run and is not used for matching.
- Splunk has no test button. A
POSTwith an empty JSON object ({}) is answered as a test and opens no alert.
Related
Was this page helpful?
