Description

Deatils about Integartion

Splunk is globally used powerful platform for searching, monitoring, Indexing, and analysing machine-generated Log files in real-time. Using This SMAX - Splunk Integration App Machine generated Triggered Alerts in Splunk can be ingested in SMAX Platform to generate meaningful incidents with Infrastructure and monitored attributes details which will helps applications teams for faster problem analysis and quick resolution. This enables organizations to automate incident creation from machine alerts, enhancing operational efficiency and reducing downtime. This integration is particularly beneficial for businesses that rely on real-time data monitoring and rapid incident response. As incidents occur that impact business-critical processes and revenue streams, SMAX platform alerts the right people at the right time and with the right data to enable rapid incident resolution.

Target Market & Business Benefit

This can be used by IT Operations, Help Desk, NOCs and DevOps teams across all industries and sizes from small MSPs to Fortune 1000 Companies which having Splunk as monitoring and SMAX as ITSM platform .Splunk being the leading player in the Security Information and Event Management (SIEM) market with a market share of near about 30% with a significant concentration in the United States Region (58%) The sectors using Splunk include IT & Services (26%), Computer Software (12%), and Financial Services (5%). This shows its strong presence in tech-heavy and data-driven sectors. Using this SMAX → Splunk connector, SMAX can be used as reliable & resilient ITSM solution for these industries.

Benefits SMAX-Splunk Integration Provides

Improved Incident Response Time

By automating the incident creation process, the IT team can respond to issues more quickly, reducing mean time to resolution (MTTR).

Increased Operational Efficiency

Automation reduces the manual effort required to manage events in Splunk, allowing IT staff to focus on more strategic tasks and manage alerts through One window i.e. SMAX platform.

Enhanced Service Reliability

Proactive monitoring and automated incident management help to minimize downtime and ensure that IT services remain reliable and available

Better Resource Allocation

With intelligent incident prioritization driven from Splunk to SMAX though automated workflows in integration engine, resources can be allocated more effectively, ensuring that critical issues are addressed first with correct priority

Scalability

The integration can scale with the organization, handling increasing volumes of data and incidents as the business grows with more new use cases in future.

Streamlined Workflow Integration

Splunk integrates seamlessly with SMAX, facilitating smooth data flow and incident management using SMAX robust integration studio well developed Process logic with endpoint

Data-Driven Decision Making

Access to comprehensive data and advanced analytics enables better decision-making and strategic planning.

Integrating Splunk with SMAX creates a powerful synergy that enhances the overall efficiency and effectiveness of IT operations. This integration not only streamlines incident management but also provides valuable insights that can drive continuous improvement.

SMAX-Splunk Integration Use case

  • An Alert is created in Splunk out of one or Triggered Event through search head.
  • For every Alert create or update action, a SMAX webhook is triggered in Splunk
  • The webhook in Splunk pushes the data to the listener in the SMAX Integration Studio.
  • The Splunk scenario associated with the listener is triggered.
  • The scenario creates or updates the Incident in Service Management.
  • It syncs Important Splunk event details like , Monitored Hostname unique Splunk Alert ID, SID , CPU usage , Splunk Alert Name , Splunk Index Name, Splunk Alert Priority, Splunk Event URL etc show it as comment in Ticket.
  • Automatically finds and adds the CI in Incident ticket from hostname present in Alert.
  • Check at integration engine with unique alert ID to avoid duplicate tickets

Minimum Requirements

  • Splunk Enterprise Edition Application is installed & configured with valid licence
  • Required port are open and listening - 9997, 8089 , 8086
  • Splunk Universal Forwarders are Installed on all the devices for monitoring
  • Alerts defined and Log files set up done
  • Monitored Devices CIs are present in SMAX with same HostName as in Splunk

Releases

Release
Size
Date
Splunk-SMAX Integration v1.0
886.6 KB
  |  
Apr 17, 2025
More info Less info
Product compatibility
Version 24.4
Version 25.1 · 25.2
Release notes

Initial creation of the Splunk-SMAX Integration with below use cases & feature

  • Splunk Triggered alert Creating Auto Incident ticket to SMAX through webhook & integration scenario developed.
  • Search for existing Incident ticket if any using unique splunk alert ID to avoid duplication.
  • Sync unique Splunk Alert ID & parameters details in Incident
  • Sync Splunk SID Event Link details in SMAX Incident.
  • Sync Splunk Event Attributes details in SMAX Incident , attributes like Monitored Hostname unique , Splunk Alert Name , Splunk Index Name, Splunk Alert Priority, Splunk Event URL etc show it as comment in Ticket.
  • Automatically finds and adds the CI in Incident ticket from hostname present in Alert
    Check at integration engine with unique alert ID to avoid duplicate tickets
Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-4-2-6380 | Tue Apr 15 15:26:15 PDT 2025