Alerting

Splunk alert to post a notification in Teams

meenu_2017
Explorer
I’m trying to configure a Splunk alert to post notifications to Microsoft Teams, but I’m running into issues with both the webhook option and the ‘MS Teams: Publish to Channel’ method. I’d really appreciate any guidance or best practices on getting this set up.
Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

MS teams has changed how those web hooks are done/works. Be sure that you are using those new. 

Update 4/14/2026: New information related to Office 365 Connectors Retirement in Teams – Final Deprecation

https://splunk.github.io/splunk-alerts-for-microsoft-teams/Configuration/

https://devblogs.microsoft.com/microsoft365dev/retirement-of-office-365-connectors-within-microsoft-...

I haven't created lately any new and as old ones have still working I haven't have look those deeper what this change really is.

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

MS teams has changed how those web hooks are done/works. Be sure that you are using those new. 

Update 4/14/2026: New information related to Office 365 Connectors Retirement in Teams – Final Deprecation

https://splunk.github.io/splunk-alerts-for-microsoft-teams/Configuration/

https://devblogs.microsoft.com/microsoft365dev/retirement-of-office-365-connectors-within-microsoft-...

I haven't created lately any new and as old ones have still working I haven't have look those deeper what this change really is.

meenu_2017
Explorer

Thank you for the pointers! The docs for the Splunk alert for Teams took me to the logging and showed me that the channel I was trying to hit is a private channel and hence failed to send the notifications. Tried pointing to a different channel and is working as intended.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
One other option if nothing else is working. Is just check email address of this channel. Then send alert via email to this channel instead of real team alerts. Of course this is not show as nicely than real teams alerts, but anyhow you will get those into teams channel.

livehybrid
SplunkTrust
SplunkTrust

Hi @meenu_2017 
Please could you let us know what issues you are having and what you have done so far to try and remediate this? 

Have you been able to confirm that the alert has fired with events that should have gone to teams? Were you able to find any errors/logs in _internal index about the alert to Teams which should have fired?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

meenu_2017
Explorer

Thank you for the response! I didnt had access to internal logs so didn't had a way to check what's going on even though the alerts were triggering. This documentation took me to the right spot for logs and pinpointed my issue - https://splunk.github.io/splunk-alerts-for-microsoft-teams/Configuration/ 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...