<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: webhook error in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/webhook-error/m-p/559315#M10635</link>
    <description>&lt;P&gt;#metoo&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 21:54:57 GMT</pubDate>
    <dc:creator>morethanyell</dc:creator>
    <dc:date>2021-07-13T21:54:57Z</dc:date>
    <item>
      <title>webhook error</title>
      <link>https://community.splunk.com/t5/Alerting/webhook-error/m-p/509437#M9319</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Alert is getting triggered, sendmail works fine but webhook not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i search&lt;STRONG&gt;&amp;nbsp;index=_internal action=webhook&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I see below error :&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sendmodalert&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;action=webhook&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Execution&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;alert&lt;/SPAN&gt; &lt;SPAN class="t"&gt;action&lt;/SPAN&gt; &lt;SPAN class="t"&gt;script&lt;/SPAN&gt; &lt;SPAN class="t"&gt;failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;INFO sendmodalert - action=webhook STDERR - Sending POST request to url=http://XXXXXXXX/ with size=448 bytes payload&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;And in the splunkd.log i see below error :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;BR /&gt;07-15-2020 18:35:41.311 +0200 WARN ScriptRunner - Killing script, probably timed out, grace=5sec, script="bla/bla/splunk/etc/apps/alert_webhook/bin/webhook.py --execute"&lt;BR /&gt;07-15-2020 18:35:41.314 +0200 ERROR sendmodalert - action=webhook - Execution of alert action script failed&lt;BR /&gt;07-15-2020 18:35:41.314 +0200 ERROR sendmodalert - Error in 'sendalert' command: Alert script execution failed.&lt;BR /&gt;07-15-2020 18:35:41.314 +0200 ERROR SearchScheduler - Error in 'sendalert' command: Alert script execution failed., search='sendalert webhook results_file=&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I have to pass the token also along with the url in the webhook configuration page ?&lt;/P&gt;&lt;P&gt;Currently in the triggeracgtion -&amp;gt; Webhook&amp;nbsp; -&amp;gt; url -&amp;gt; i have just added the client url like this : &lt;A href="http://IPof" target="_blank"&gt;http://IPoftheclientmachine&lt;/A&gt;:port/&lt;/P&gt;&lt;P&gt;DO i have to append this with some token or something else at the end of the url ?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 02:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/webhook-error/m-p/509437#M9319</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-07-16T02:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: webhook error</title>
      <link>https://community.splunk.com/t5/Alerting/webhook-error/m-p/559315#M10635</link>
      <description>&lt;P&gt;#metoo&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 21:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/webhook-error/m-p/559315#M10635</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2021-07-13T21:54:57Z</dc:date>
    </item>
  </channel>
</rss>

