Skip to main content

Splunk On-Call alerts

Send kwatch incident alerts to Splunk On-Call. Use the interactive manager for installation and credential setup. This page explains the provider fields and shows a minimal configuration fragment.

Before you start, have these values ready:

  • apiKey — API key.
  • routingKey — Routing key.

Credentials, tokens, keys, passwords, and webhook URLs must be mounted from a Kubernetes Secret. Use an exact ${file:/absolute/path} reference for every field marked Secret.

Configuration​

FieldTypeRequiredSecretValidationDefaultDescription
apiKeystringyesyes——API key
routingKeystringyesyes——Routing key
urlstringnonourl—Optional endpoint override
routesjsonnonojson—Optional JSON route filters.
retry.maxAttemptsintegernonointeger—Optional maximum retry attempts.
retry.delaystringnono——Optional retry delay, for example 5s.
fallbackstringnono——Optional fallback provider name.

Minimal example​

alert:
splunkoncall:
apiKey: "${file:/config/splunkoncall-apiKey}"
routingKey: "${file:/config/splunkoncall-routingKey}"

Add routes, retry, and fallback when you need delivery filtering or recovery. See the channels overview for guidance, or the complete provider reference for the catalog-wide view.