Alerting

Splunk and MS Teams

jesusreyes
New Member

I am looking for documentation on how to use Splunk with MS Teams. I want to forward alerts to groups in MS teams.

0 Karma

jaxjohnny2000
Builder

splunkbase.splunk.com/app/3375/  has been archived.

This one will do what you need. It's easy to setup 

https://splunkbase.splunk.com/app/4787  - It creates O365 Cards. You can set different Icons and colors for different alerts.  

Provides an alert action to easily send Office 365 Cards to a Microsoft Teams channel using the Incoming Webhook Connector in Teams. Easily send beautiful alerts with customizable text or search data included with the Card. (copied from splunkbase)

https://www.groundsecurity.com/splunk-app-microsoft-teams-alert-cards/ 

So far, works everytime.  

I have not figured out how to create the "alert" notification where the little channel lights up, but the cards do show up in the teams channel. 

 

 

0 Karma

ajzodak
New Member

This Add on is only supported for Splunk Enterprise and not for Cloud. can you pls let me know if there is any add on for Splunk cloud support ?

0 Karma

amitm05
Builder

I think this is the one shall suit your purpose -
https://splunkbase.splunk.com/app/3375/

This is a webhook based, so your Teams channel URL should go to the Webhook of the Real time alert

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...