Splunk Alert Events Integration
Sync Splunk alert events to Flashduty via webhook for automated alert noise reduction.
In Flashduty
You can obtain an integration push URL through either of these two methods:
Using Private Integration
Choose this method when you don't need to route alert events to different channels. It's simpler and recommended.
Expand
- Go to the Flashduty console, select Channel, and enter a specific channel's details page
- Select the Integration tab, click Add Integration to enter the integration page
- Choose Splunk integration and click Save to generate a card
- Click the generated card to view the push URL, copy it for later use, and you're Done
Using Shared Integration
Choose this method when you need to route alerts to different channels based on the alert event's payload information.
Expand
- Go to the Flashduty console, select Integration Center=>Alert Events to enter the integration selection page
- Select Splunk integration:
- Integration Name: Define a name for this integration
- Configure the default route and select the corresponding channel (after the integration is created, you can go to
Route
to configure more routing rules) - Click Save and copy the newly generated push URL for later use
- Done
In Splunk
I. Splunk Alert Push Configuration
- Log in to your Splunk console
- In the
Search and Report
application, search for keywords you want to monitor, such as "error" - In the upper right corner's save menu, select
Alerts
to configure the search keywords as monitoring items

- In the configuration popup, enter relevant information. Configure the
set up
andTriggering conditions
sections according to your needs - In the
Trigger Action
section, clickAdd Action
and selectWebhook

- In the
Webhook
section, enter the integration push URL in theURL
field (the URL will be generated after saving the integration name on the current page) and save to complete the alert configuration

II. Status Mapping
Since Splunk alert events don't differentiate severity levels, all alert events pushed from Splunk to Flashduty will have a Warning status and won't include recovery events.
修改于 2025-03-27 07:52:02