EvoHub Docs Sign in

Integrations

Splunk

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

EvoHub receives Splunk alerts through the Webhook alert action. Each time an alert triggers, EvoHub opens an alert with the first result row. Splunk does not send a notification when the condition clears, so these alerts are resolved in EvoHub.

Set it up

Create the integration

In EvoHub, go to On-Call → Integrations → + Add Integration, choose Splunk, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.

Allow the URL (Splunk 9.0 and later)

Add your webhook URL to Splunk's webhook allow list. Splunk refuses to call a URL that is not on it.

Add the action

Open the saved search, choose Edit Alert, and under Trigger Actions add Webhook with your webhook URL.

Splunk's webhook body is read as it is:

{
  "search_name": "Failed root logins",
  "result": { "host": "web-07", "count": "8" },
  "sid": "scheduler_admin_search_W2_at_14232356_132",
  "results_link": "https://splunk.example.com/app/search/@go?sid=...",
  "owner": "admin",
  "app": "search"
}

What EvoHub reads

EvoHub alert Taken from
Title search_name, plus " on host" when the result has a host field.
Description The first result row as field: value lines (internal fields other than _raw are left out).
Labels app, owner, host, sid, and url (the results_link).
Fingerprint The search name, plus host when present.

Severity

If the result row has a severity field, EvoHub uses it: critical, high, medium, low or info (error reads as high, warning as medium). Set it in the search, for example:

... | eval severity="critical"

Without one, Splunk alerts are high.

Resolve and deduplication

  • Splunk sends no recovery notification. Resolve the alert in EvoHub when the problem is fixed.
  • Each run of the same search for the same host, while the alert is open, is recorded as Retriggered. The search ID changes every run and is not used for matching.
  • Splunk has no test button. A POST with an empty JSON object ({}) is answered as a test and opens no alert.

Last updated