guilhemmarchand / TA-jira-service-desk-simple-addon

Atlasian JIRA add-on for Splunk alert actions
11 stars 8 forks source link

Incident Review Manual AR Issue #41

Closed dntml closed 4 years ago

dntml commented 4 years ago

Hi Guilhem!

Good day, I've encountered an issue wherein the Jira Service Desk is working when used as an Alert Actions in an Alert or Saved Search but not working when using manually as Adaptive Response Actions in ES.

As an Alert Actions: "2020-09-18 16:08:21,877 INFO pid=29505 tid=MainThread file=cim_actions.py:message:425 | sendmodaction - worker="splunk-searchhead" signature="JIRA Service Desk ticket successfully created. https://jira.test.com/rest/api/2/issue, content={"id":"12345","key":"sample ticket","self":"https://jira.test.com/rest/api/2/issue/12345"}" action_name="jira_service_desk" search_name="test_alert Clone" sid="scheduler_ZGFuLnRpbW9sYQ__search__RMD5820739fbb14d0d0f_at_1600445280_95_9D504CCB-88B6-41EF-B167-0BB462CC73D6" rid="0" app="search" user="admin" digest_mode="1" action_mode="saved" action_status="success"

In AR: image

Thanks, let me know if you need further details.

guilhemmarchand commented 4 years ago

Thank you for reporting it @dantimola

The issue could be identified and is linked with the alert_actions.conf configuration file, when running in AR mode (adhoc), all fields used by the alert action have to been explicitly defined in this file. With the addition of new features over time, its configuration became incomplete.

Version 1.0.19 will be released very soon.

Guilhem

guilhemmarchand commented 4 years ago

@dantimola Fixed in version 1.0.19 which is now live in Splunk Base