Alerting

Send alert notifications to Microsoft Teams using Splunk enterprise

chinnawatj
Explorer

Due to Office 365 connectors in Microsoft Teams will be retired.
Have anyone success to transit from Office 365 connectors to Workflows in the splunk enterprise solution?
Could anyone give me some document to do this or the workflow template that work with the splunk enterprise solution?

Labels (2)
0 Karma

zZeb
Explorer

We use emails as alert outputs, arriving to a shared mailbox, getting alerts from other products as well. Then we have a power automate listening to the mailbox, catching those alert emails and sending a notification in a chat group with the whole team. Works nicely, removing all the integration pain from how many tools we use.

chinnawatj
Explorer

It sound like a good idea.

0 Karma

jawahir007
Communicator

Try Splunk webhook action in alert settings.

In  Teams you can configure the settings as shown here (To create webhook URL in Teams) : https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/add-incomin...

0 Karma

chinnawatj
Explorer

I think the microsoft Webhook will be EOL in the end of this year,  and I have heard that we need to migrate to use the workflow app in team.Does anyone have the solution with that

0 Karma

Splunk-M
New Member

Did you come up with any solution? 

I'm curious how you had the webhook working with MS Teams before?
I never could get the default Splunk Webhook action to properly send to the Teams Webhooks integration. It seemed like the default Splunk Webhook json is not formatted in a way that Teams accepts?

0 Karma

JKelley
Engager

I'm having issues with this transition as well and have not found a solution yet.  Anyone?

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...