Div | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||||||
|
...
- From the Alerts page, click Open in Search beside the desired alert.
Alternatively, run a new search. Ensure the following condition is included in the search:
where
innullisnull(self)
For example:Code Block language sql index=* "FATAL" | where isnull(self)
This condition excludes the new JSD ticket from subsequent searches, ensuring that Splunk opens only one ticket each time the alert is triggered.
- Go to Save As > Alert.
- At the bottom of the window, click Add Actions, and then select JIRA Service Desk Ticket.
- Enter the connection details, and click Save.
Insert excerpt _SplunkConfigurationServer _SplunkConfigurationServer nopanel true
The next time the search generates an alert, it will automatically create a ticket in your JSD instance.
...