|
You can configure Splunk to automatically open a ticket in JIRA Service Desk (JSD) when a saved search generates an alert. |
To automatically create JSD tickets from Splunk alerts, add an action to the alert in Splunk.
Ensure the following condition is included in the search: where isnull(self)
For example:
index=* "FATAL" | where isnull(self) |
This condition excludes the new JSD ticket from subsequent searches, ensuring that Splunk opens only one ticket each time the alert is triggered.
Analyze data and configure reports in Splunk.