alertmanager / alert_manager

Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features
Other
81 stars 44 forks source link

feature request: Forward events out of splunk to API #136

Open eloquentvgon42 opened 8 years ago

eloquentvgon42 commented 8 years ago

I am not sure if this is related to "Support for customized workflow" in the feature request noted in the wiki. However I would like to suggest an option to forward alerts to external systems via various output types i.e: syslog, snmp, or API using REST or SOAP etc. built in a as workflow step would be spectacular.

thanks

eloquentvgon42 commented 8 years ago

I'm not sure if there is any way to take advantage of the email alert system? Using the same process to fire a syslog message containing the required data instead of sending it to the email application?

simcen commented 8 years ago

Thanks for your request, we are still thinking about possible extensions. Initially, the feature "Custom incident handler" on the roadmap was intended exactly for your needs. However, the idea and concept is very similar to the Modular Alert action framework in Core Splunk. So at the moment, we are struggling with the decision how we could leverage the Modual Alert action framework or if we have to build something on our own to support our custom events.

Anyway, thanks again for posting this. It helps us to see that there is real need for something like that.

eloquentvgon42 commented 8 years ago

Understood, thanks for the response I am looking forward to working with alert manager as it evolves