Notification types
Splunk On-Call offers many notification options including email, SMS, phone, and push notifications. This topic highlights each of the different options.
Splunk On-Call offers many notification options, including email, SMS, phone, and push notifications. This topic highlights each of the different options.
You can also configure delayed notifications for alerts that may auto-resolve within a set time frame. For details, see Configure delayed notifications.
Push notifications
Push notifications are sent through the application. We use push for:
-
Paging
-
On-call changes
-
Chats (timeline and private)
-
Control Call
-
Upcoming on-call shift reminders.
When a push notification is used to deliver a page, you will have the option to acknowledge, reroute, or snooze the incident straight from the notification.
SMS notifications
SMS notifications can be used in your personal paging policy. The message you receive is, at most, 160 characters, and it displays the incident number, entity_display_name, and response code if two-way SMS is supported. When you receive an SMS notification, two codes are included in the message so you can acknowledge aor resolve the alert by responding with the correct five-digit code. These response codes expire after 1 hour.
Early on-call notifications
Splunk On-Call can notify you before a scheduled on-call shift begins so you have time to prepare for handoff. By default, Splunk On-Call sends the notification 12 hours before the shift starts.
earlynotifications feature flag and are disabled by default.
Early on-call notifications are sent by mobile push notification and email, and Splunk On-Call also records a timeline event. The mobile push notification uses the title Upcoming On-Call shift and tells you when your shift starts and which team and policy the shift applies to.
Early on-call notifications are separate from the notification that tells you when you are now on call. The early notification is a reminder before the shift starts, while the on-call notification confirms that the shift has started.
Early on-call notifications apply to standard rotations, 24/7 shifts, partial shifts, and multiple rotation groups. Splunk On-Call sends one notification per shift, even if you are included in multiple escalation policies for the same shift.
SMS subscription management
You may stop and start our SMS notification subscription by replying to the message with STOP or START. However, we recommending manage your notifications from the personal profile page in Splunk On-Call.
WhatsApp notifications
You can use WhatsApp notifications in your personal paging policy. To enable WhatsApp, download and configure the WhatsApp application from the Apple App Store or Google Play Store. Next, access your user profile in Splunk On-Call and enter and verify your mobile number. After verification, an Enable WhatsApp button will appear next to the number and you’ll be able to use WhatsApp in your Paging Policy.
Email notifications
Emails can be used for pages. Emails can also be used as reminders that your Splunk On-Call instance is in maintenance mode, or that you have a gap in your schedule due to a scheduled override that is not covered. Splunk On-Call can also send email reminders before scheduled on-call shifts begin.
Scheduled override:
Maintenance mode:
Phone notifications
Phone calls are used for paging. The entity_display_name field is read aloud and then the following options to acknowledge or resolve the alert are offered:
-
Press 4 to acknowledge
-
Press 6 to resolve
Phone call notifications can be delivered in a supported language other than English. When enabled for your organization, each user can set a preferred language and hear system prompts, instructions, and confirmation messages in that language. For details, see Phone call language translations.
For a list of phone numbers used by Splunk On-Call, see Get started with the mobile app.