Alerting

Send alert notifications to Microsoft Teams using Splunk enterprise

chinnawatj
Explorer

Due to Office 365 connectors in Microsoft Teams will be retired.
Have anyone success to transit from Office 365 connectors to Workflows in the splunk enterprise solution?
Could anyone give me some document to do this or the workflow template that work with the splunk enterprise solution?

Labels (2)
0 Karma

zZeb
Explorer

We use emails as alert outputs, arriving to a shared mailbox, getting alerts from other products as well. Then we have a power automate listening to the mailbox, catching those alert emails and sending a notification in a chat group with the whole team. Works nicely, removing all the integration pain from how many tools we use.

chinnawatj
Explorer

It sound like a good idea.

0 Karma

Jawahir
Communicator

Try Splunk webhook action in alert settings.

In  Teams you can configure the settings as shown here (To create webhook URL in Teams) : https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/add-incomin...

chinnawatj
Explorer

I think the microsoft Webhook will be EOL in the end of this year,  and I have heard that we need to migrate to use the workflow app in team.Does anyone have the solution with that

0 Karma

Splunk-M
New Member

Did you come up with any solution? 

I'm curious how you had the webhook working with MS Teams before?
I never could get the default Splunk Webhook action to properly send to the Teams Webhooks integration. It seemed like the default Splunk Webhook json is not formatted in a way that Teams accepts?

0 Karma

JKelley
Engager

I'm having issues with this transition as well and have not found a solution yet.  Anyone?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...