# Splunk

EvoHub receives Splunk alerts through the **Webhook** alert action. Each time an alert triggers, EvoHub opens an alert with the first result row. Splunk does not send a notification when the condition clears, so these alerts are resolved in EvoHub.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Splunk**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Allow the URL (Splunk 9.0 and later)
Add your webhook URL to Splunk's webhook allow list. Splunk refuses to call a URL that is not on it.
### Add the action
Open the saved search, choose **Edit Alert**, and under **Trigger Actions** add **Webhook** with your webhook URL.
:::

Splunk's webhook body is read as it is:

```json
{
  "search_name": "Failed root logins",
  "result": { "host": "web-07", "count": "8" },
  "sid": "scheduler_admin_search_W2_at_14232356_132",
  "results_link": "https://splunk.example.com/app/search/@go?sid=...",
  "owner": "admin",
  "app": "search"
}
```

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `search_name`, plus " on `host`" when the result has a `host` field. |
| Description | The first result row as `field: value` lines (internal fields other than `_raw` are left out). |
| Labels | `app`, `owner`, `host`, `sid`, and `url` (the `results_link`). |
| Fingerprint | The search name, plus `host` when present. |

### Severity

If the result row has a `severity` field, EvoHub uses it: `critical`, `high`, `medium`, `low` or `info` (`error` reads as high, `warning` as medium). Set it in the search, for example:

```text
... | eval severity="critical"
```

Without one, Splunk alerts are **high**.

## Resolve and deduplication

- Splunk sends no recovery notification. Resolve the alert in EvoHub when the problem is fixed.
- Each run of the same search for the same host, while the alert is open, is recorded as **Retriggered**. The search ID changes every run and is not used for matching.
- Splunk has no test button. A `POST` with an empty JSON object (`{}`) is answered as a test and opens no alert.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Graylog](https://docs-dev.evohub.io/graylog.md)
