Receiving Splunk On-Call (Formerly VictorOps) Alerts

Here's how to set up a webhook to receive Splunk On-Call (Formerly VictorOps) alerts in Transposit.

Once configured, you can:

  • route Splunk On-Call alerts to Transposit and Slack
  • create activities and run runbooks tied to Splunk On-Call alerts
  • trigger runbooks to run when Splunk On-Call alerts are received
  • trigger runbooks to run when the payload's content matches your conditions
  • trigger runbooks to run when an activity is created in response to Splunk On-Call alerts
  • invoke actions to remediate the underlying issues triggered by Splunk On-Call
  • set dynamic parameters using payloads provided by Splunk On-Call alerts

Follow the steps below to integrate Splunk On-Call alerts with Transposit.

1. Create Splunk On-Call Alert Webhooks in Transposit#

Go to Settings > Webhooks, and click Add webhook. Choose Splunk On-Call (Formerly VictorOps), as shown below.

Note: The optional Slack channel must already exist, create it before adding the webhook.

Click Add and then find the webhook you just added in the list. Click Click to copy to copy the URL to the clipboard or manually copy the endpoint URL.

2. Set Up Webhooks in Splunk On-Call#

In Splunk On-Call, navigate to Integrations > Outgoing Webhooks and click Add Webhook, as shown below.

Set the Event dropdown to Incident-Triggered, the To field to the Endpoint URL you copied from Transposit, as shown below, and click Save.

3. Trigger Incidents in Splunk On-Call#

Splunk On-Call is now setup to call this webhook for new incidents. You can test the webhook by creating an incident, as shown below.

When you click Create incident above, you should see events appearing in Transposit and, optionally, in Slack.

4. Integrate Splunk On-Call Alerts in Transposit#

With Splunk On-Call webhooks set up, you can do the following in Transposit.

4.1 Receive Alerts#

When a Splunk On-Call incident is triggered, you should see alerts displayed as events in Transposit, as shown below.

In Slack, if you defined the webhook in Transposit to support Slack, you should see Splunk On-Call alerts displayed, too, as shown below.

4.2 Create Activities#

When an alert is received in Transposit or Slack via the Splunk On-Call webhook, click the Create activity button to create a new activity, add runbooks, and follow the progress of work done by your team in response to Splunk On-Call alerts.

4.3 Trigger Runbooks#

If you have added runbook triggers based on Splunk-On Call alerts, the runbook will start automatically when a Splunk On-Call alert is received.

Alternatively, you can specify that the runbook should start only when an activity is created from the webhook, as shown below.

4.4 Add Dynamic Parameters#

If you have defined dynamic Splunk On-Call alert parameters while adding runbook actions, as shown below, their values will be populated by the Splunk On-Call alert's payload when the actions are executed during runbook runs.

Next Steps#