Alerting

Alerts: Webhook Trigger Action and Slack Incoming WebHooks Custom Integration

dwspncr
Explorer

I have an Alert that successfully creates an entry in Trigger History via the "Add to Triggered Alerts" Trigger Action; however, the Webhook Trigger Action for the same Alert does not appear to fire.

The webhook URL (of the form https://hooks.slack.com/services/#########/#########/########################) is generated by Slack's Incoming WebHooks Custom Integration, and making a curl request to it is successful.

Any suggestions on how to debug this are appreciated.

dwspncr
Explorer

Using the Slack Webhook Alert add-on, as @aaraneta mentions, works.

I'm still not entirely satisfied, though, as all the documentation that I've read seem to indicate that "standard" webhooks should work.

chadwell
Explorer

I'm hoping someone can answer this.

Using the provided 'webhook' functionality (without any additional apps etc) - how can we POST to a slack web hook.

I can use Postman on my laptop to post to the slack channel without issue. But when the splunk alert is triggered the webhook seems to do nothing.

Any ideas?>

0 Karma

known_user
Engager

How can we integrate without having to configure anything at the splunk enterprise level?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@dwspncr - Are you using the Slack Webhook Alert add-on in Splunkbase? Or a different Slack related app/add-on in Splunkbase? I just want to make sure your post is tagged appropriately for best visibility. Thank you.

0 Karma

dwspncr
Explorer

No add-ons. I was hoping to get it to work using a plain webhook post to Slack.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...