Repository navigation
Frequently Asked Questions (FAQ)
Note: The documentation for Alert Manager v2.0 has been relocated to http://docs.alertmanager.info/Documentation
There are many naming standards to classify incidents. Alert Manager follows ITIL framework naming, where priority is calculated from impact and urgency ( impact x urgency = priority ). To simplify configuration we use Splunk's alert serverity setting (or «alert.severity» property in savedsearches.conf) as the impact level. The urgency is taken from the incident configuration's default urgency setting, or, if the alert has a field urgency with a valid setting, from the alert's result. For alerts with multiple urgencies, the first urgency level is taken. Urgencies can be overridden manually after an incident has been created.
The incident's priority is calculated with the help of the alert_priority lookup table based on the alert's severity reps. impact and the inicident's urgency. The default matrix can be found in a seperate wiki page.
The alert manager script (alert_handler.py) is used "globally", so independent to an app. Alert scripts not bound to an app need to be place in $SPLUNK_HOME/bin/scripts. To ensure app updates of the alert manager getting correctly installed, we decided to leave to script itself in the app folder and just symlink it so it can be used from anywhere.
-
Open a command prompt with administrative privileges (Start -> Type 'cmd' -> Right-click on cmd.exe -> Click 'Run as administrator'
-
Go to the $SPLUNK_HOME/bin/scripts directory:
cd "C:\Program Files\Splunk\bin\scripts" -
Create symbolic link with "mklink":
mklink alert_handler.py ..\..\etc\apps\alert_manager\bin\alert_handler.py
There are two main reasons why we are using users in our app:
- Incident assignment: Dispatch incident investigation tasks to other collegues
- Notifications: Receive notifications at different stages by e-mail
Built-in users are traditional Splunk users. They can be used to re-assign incidents and receive notifications as long as the built-in user repository is activated (see User settings in the Alert Manager).
Alert Manager users are virtual users configured in the Alert Manager only. The primary usage of these users is to represent user or group accounts outside of Splunk.
- Example 1: You wan't to notify or dispatch an incident to a Domain controller admin when a new Incident has been created, but the admin has no account in Splunk
- Example 2: You wan't to send a notification to a mailing list without having to create a dedicated Splunk user for this purpose.