Stjubit / TA-alert_forwarder

Splunk Technical Add-on that adds an Alert Action which forwards Alerts to a Splunk HTTP Event Collector
GNU General Public License v3.0
4 stars 1 forks source link

idea: adding alert id or (better) sid to more of the addon logs #3

Open awx-vsyr opened 2 years ago

awx-vsyr commented 2 years ago

Hello Julian,

Do you think it would be useful/would you be interesting in adding the sid and or alert id to more of the log messages. (success and error). Although I'm not sure how uniformly alertid is available, since it's guid generated in the addon py but perhaps sid is more uniformly available across the different parts of the app . Having a SID in more of the messages, would make it easier to narrow down issues associated with a specific search run or validating when multiple alerts have triggered around the same time and to diff/join it to scheduler/audit log or jobs rest api 'your favourite self search with resultsCount >0' :)