Skip to main content
Incident Managemnet for Splunk app icon

Incident Managemnet for Splunk

Universal, lightweight Incident Management app for Splunk Core. Consolidates alerts & signals from Splunk, Dynatrace, Datadog, AWS & Azure into KV Store episode clusters with interactive triage drawers, audit logs & SLA response analytics at 0% extra license cost.Built by Venkatesh Geriti
splunk product badge

Default Version 1.0.3

August 14, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x, 5.x

Rating
4
(1)

Log in to rate this app

Support
Developer Supported

Splunk Incident Management (`splunkIM`) is a lightweight, universal incident response platform built natively for Splunk Core and Splunk Cloud Platform. It acts as a central Incident Command Console that consolidates alert signals, anomalies, and problem notifications from diverse observability sources — including native Splunk Saved Searches, Dynatrace® Davis AI Problems, Datadog® Monitors, AWS® CloudWatch Alarms, Azure® Monitor, and Security Findings — into unified, actionable 24-hour incident episodes. ### Key Capabilities & Highlights: • Universal Multi-Source Aggregation: Consolidates raw summary alerts and problem notifications across security, APM, and cloud infrastructure into a single unified incident queue. • 0% Additional License Impact: Leverages standard Splunk Summary Indexing (index=summary marker="app=splunkIM"). Summary index events do NOT count against daily Splunk ingestion license limits. • Stateful KV Store Episode Tracking: Maintains real-time incident states (New, Acknowledged, Active, Blocked, Resolved, Closed) with full user attribution and edit history using high-performance KV Store collections. • Raw-to-Target Severity Value Mapper: Built-in matrix in the Settings console to translate custom raw alert string severities (e.g. P1_EMERGENCY, FATAL_99, AVAILABILITY) into standard severity levels (Critical, High, Medium, Low, Info). • Live SLA Response Metrics: Real-time executive dashboards tracking Mean Time to Acknowledge (MTTA) and Mean Time to Resolve (MTTR). • Interactive Triage Drawer: Analysts update status, assign team members (populated live from Splunk user accounts), add work notes, and inspect underlying raw summary events without leaving Splunk. • Automatic Episode Re-opening: Re-triggers existing resolved incidents if a matching alert fires within the 24-hour SLA window. --- ℹ️ Disclaimer: All product names, logos, and trademarks (such as Dynatrace®, Datadog®, ServiceNow®, PagerDuty®, AWS®, Azure®) are property of their respective owners and used for identification and compatibility purposes only.