Splunk® IT Service Intelligence

Administration Manual

Acrobat logo Download manual as PDF

Splunk IT Service Intelligence version 4.0.x reached its End of Life on January 19, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Plan an upgrade of IT Service Intelligence.
This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. Click here for the latest version.
Acrobat logo Download topic as PDF

Set up custom episode actions in ITSI

Episode actions have the same prerequisites as custom alert actions in Splunk Enterprise. See Custom alert actions overview in Developing Views and Apps for Splunk Web.

  1. Create a local version of SPLUNK_HOME/etc/apps/SA-ITOA/default/notable_event_actions.conf.
  2. Add a stanza for the action you want to perform. For example: [itsi_sample_event_action_ping]
  3. Set disabled=0 to enable the custom action.
    For example:
    disabled = 0

Setting up custom alert actions via notable_event_actions.conf only allows for a one-way integration. The episode will not contain a drilldown link to the action that was performed.

Last modified on 22 February, 2019
Manage notable event indexes in ITSI
Tune notable event grouping in ITSI

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.0, 4.1.1, 4.1.2, 4.1.5

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters