STRAX Reach · Alerts and push
Open Splunk On-Call incidents from Reach
Teams that run on Splunk On-Call can open an incident straight from a client conversation, routed with the routing keys they already use.
- REST endpoint alerts
- Routing keys
- One incident per message
Routing keys decide who is paged
Reach posts to the Splunk On-Call REST endpoint integration with the integration key held in the credential vault. The routing key comes from the escalation contact's address, or from a default setting when the contact is addressed as default.
The message subject becomes the incident title that on-call engineers see and hear read out, and the text becomes the state message. The entity id is built from the Reach message id, so repeated sends of the same message roll up into one incident.
Splunk On-Call was known as VictorOps before Splunk bought it, and the REST endpoint still carries that heritage in its address. Existing routing rules, escalation policies and rotations need no changes for Reach.
A message type setting decides how loud Reach escalations are: critical opens an incident and starts paging, while warning or info only adds an entry to the timeline. Staging can stay on warning while production uses critical.
Where it helps
Settlement file delays
Open an incident for the operations rota when merchants report that yesterday's settlement has not arrived.
Airtime vending failures
Page the vending platform team when resellers report failed airtime or data purchases.
Weekend escalations
Route urgent client issues to whoever holds the weekend rotation without anyone searching for a phone number.
Chargeback spikes
Open a warning on the risk rotation timeline when disputed card transactions reported by clients climb unusually fast.
What you need
-
The REST endpoint integration
Enabled in Splunk On-Call, with its key stored in the STRAX credential vault.
-
Routing keys
One per team or rotation you want to reach, used as escalation contact addresses.
-
Default routing and message type
Set per environment in the Reach settings.
-
Reach Core
Where escalation messages are queued and recorded.
Good to know
This channel opens incidents only. Acknowledging and resolving stay in Splunk On-Call and are not reflected in the Reach conversation yet.
Questions
How do we reach a specific rotation?
Give its escalation contact the routing key as address. Contacts addressed as default use the default routing key setting.
Why is the integration key kept in the vault?
It is part of the endpoint address and grants anyone who has it the power to page your teams, so it lives with the other secrets.
What if Splunk On-Call refuses the alert?
The message is marked failed with the reason Splunk On-Call returned, so the agent can escalate another way.
Can staging page anyone?
Set staging to warning and a test routing key, and its alerts only reach the timeline of that test route.
Read more
-
The whole Reach family →
Reach Core and every channel package, with what each one needs.
Add Splunk On-Call to Reach
Tell us which channels your clients use and we will plan the rollout with your team.
Premium Requires STRAX Reach - Core, which is licensed.
About this listing
| Version | 1.0.0 |
| Author | STRAX |
| Category | Communication |
| Published | 2026-09-24 |
What's inside
| Credential | 1 |
| Global variable | 2 |
| Workflow | 1 |
What happens on install
After the import, and only with your consent, the installer runs:
- Reach - Register Channel : Registers the Splunk On-Call channel with Reach Core, disabled until its credentials are entered
Free listing
Install it from Feature Marketplace inside STRAX
It builds on STRAX Reach - Core, a premium package. Ask us for a quote to license it first.
Open Feature Marketplace
In your STRAX installation, open Feature Marketplace from the navigation.
Find "STRAX Reach - Splunk On-Call"
Search or browse to this listing and review the contents disclosure; every package shows what it contains before anything runs.
Install
Choose Install, or "Customise with AI" to adapt the package to your environment first. No licence is needed for free listings.
Splunk On-Call and Splunk are trademarks of their owners, named here only to identify the service this package connects to.
See it on your own systems.
A demo takes an hour, on your data landscape rather than ours.


