Splunk On-Call
this guide explains how to connect resolve ai with splunk on call (formerly victorops) how does resolve use the splunk on call integration? resolve scrapes incidents from the splunk on call api and ingests them as alerts, so they can trigger and inform investigations during an investigation, resolve can also look up who is currently on call, read a team's or a user's on call schedule, and pull the current incident list as evidence prerequisites you will need admin access in splunk on call (only admins can manage api keys), and admin access in resolve ai (only admins can manage integrations) 1\ in splunk on call, create an api key resolve authenticates to the splunk on call rest api with an api id and an api key both come from the same page log in to splunk on call as an admin open integrations , then select the api tab copy the value shown next to your api id click + new key give the key a description, ex resolve ai check the read only box create the key, then copy the api key value from the list and store it securely use a read only key a read only key is enough to enable every feature described in this guide the api tab of the integrations page in splunk on call, showing your api id above the list of api keys and the new key button if you do not see the api tab at all, you are likely not an admin only admin users can create api keys ask a splunk on call administrator to create one for you 2\ (optional) find your routing keys if you only want resolve to ingest incidents for certain teams, you can scope the connection to one or more routing keys skip this step to ingest every incident in the organization in splunk on call, navigate to settings → routing keys https //help splunk com/en/splunk enterprise/alert and respond/splunk on call/alerts/routing keys note the names of the routing keys you want resolve to ingest routing keys tie alerts from your monitoring tools to a specific escalation policy, so they are usually the cleanest way to scope resolve to the teams you are onboarding first 3\ in resolve ai, connect splunk on call open the splunk on call integration page https //app0 resolve ai/integrations/splunkoncall/connect in resolve click add connection enter a name , ex splunk on call paste your api id from step 1 3 paste your api key from step 1 7 (optional) enter routing keys — a comma separated list, ex platform, payments team leave blank to ingest all incidents click save