Alerting

Send email alert not working sending to Microsoft Teams channel

paleewawa
Explorer

Recently our splunk security alert integration has stopped working last month (December) where we'd send an alert automatically from splunk cloud to our onmicrosoft.com@amer.teams.ms e-mail.

Is the support of this being deprecated on the Microsoft side? Or is this a whitelisting issue? Anyone else experience a similar problem?

Labels (2)

jc01480
Explorer

I'm having a similar problem. When setting up an alert notification by email, the email address for the Teams channel is not being accepted. I'm still researching the issue.

Tags (1)
0 Karma

jc01480
Explorer

Okay, this was an easy fix. Whitelist the email domain (for your Teams link) in Server Settings > Email settings. I successfully added mine after whitelisting. 

marycordova
SplunkTrust
SplunkTrust
@paleewawa you should accept this answer as a solution if it works for you also 🙂
@marycordova
0 Karma

PickleRick
SplunkTrust
SplunkTrust

If this is email-related (didn't know that there is a way to send to teams using email), I'd seek _internal for anything related to senmail.py and the destination address. I don't remember though if this data is available on Cloud. If it is not, it's probably something you'd need to go over with support.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...