Splunk Integration
Last updated
Was this helpful?
Splunk is a platform for searching, monitoring, and analyzing machine data. This integration delivers triggered Splunk alerts to ITOC360 through the ITOC360 alert action app, so alerts fired by your saved searches open incidents on your dashboard and reach the right on-call engineer.
The ITOC360 app adds a custom alert action to Splunk. When a saved search or alert triggers, the action sends the alert to ITOC360 with the search name as its title, the host from the triggering result, and the severity you selected. ITOC360 maps the severity to a priority and routes the alert through your escalation policies.
In ITOC360, go to Sources and click Add Source.
Select Splunk as the source type.
Give the source a name and save it.
Copy the generated source token — you will paste it into the alert action settings in Splunk.
Install from Splunkbase:
In Splunk Web, go to Apps → Find More Apps.
Search for ITOC360 and click Install.
Or install from file:
Download the app package from Splunkbase.
In Splunk Web, go to Apps → Manage Apps → Install app from file.
Upload the package and restart Splunk if prompted.
Run the search you want to alert on, then click Save As → Alert. Give it a title, set the schedule (for example a cron schedule), and define the trigger condition.

Under Trigger Actions, click Add Actions and select ITOC360.
Configure the action:
Source token
Token of your ITOC360 Splunk source
— (required)
Severity
Severity assigned to alerts from this action: critical, high, medium, or low
medium
Host field
Result field used as the alert host; falls back to the Splunk server name when missing
host

Click Save. The alert summary page shows ITOC360 listed under Actions.

ITOC360 maps the severity you select to an alert priority:
critical
CRITICAL
high
HIGH
medium
MEDIUM
low
LOW
Create a test alert with a search that always returns results, for example index=_internal | head 5, scheduled to run every few minutes with a trigger condition of Number of Results > 0.
Attach the ITOC360 action with your source token.
When the alert triggers, it appears on your ITOC360 dashboard with the search name as its title.
If nothing arrives, search index=_internal itoc360 in Splunk — the action logs each delivery attempt and any errors there.
Last updated
Was this helpful?
Was this helpful?

