Alerting

Webhook - error sending webhook request: HTTP Error 502 - how to resolve?

sverremoen
New Member

Hi!

I've spent a couple of weeks trying to get Webhook running on our Splunk Enterprise server (v.6.5.2). I've done what I can to find an answer to this error:
**
11-27-2018 20:45:06.296 +0100 INFO sendmodalert - action=webhook STDERR - Sending POST request to url=http://10.10.102.35:8080/generic-webhook-trigger/invoke?token=siste_sukk with size=2465 bytes payload 11-27-2018 20:45:06.296 +0100 ERROR sendmodalert - action=webhook STDERR - Error sending webhook request: HTTP Error 502: internal error - server connection terminated
11-27-2018 20:45:06.797 +0100 INFO sendmodalert - action=webhook - Alert action script completed in duration=61611 ms with exit code=2
11-27-2018 20:45:06.797 +0100 WARN sendmodalert - action=webhook - Alert action script returned error code=2
**
More info:
- I have set up a Webhook receiver on a Jenkins servers.
- The Webhook URL runs fine, and is accessible from the Splunk server, at least when ran in a browser. I do get the JSON response as expected.
- There is no network firewall blocking the traffic.

Do you have any idea what I've missed? Is there any setup that is required on the Splunk Enterprise server in order to get it running? Any thoughts on what to troubleshoot?

Best Regards,
Sverre

0 Karma

hettervik
SplunkTrust
SplunkTrust

Hi Sverre! Did you ever find a solution to this problem? I'm experiencing the same problem myself it seems.

0 Karma

naliniasb
Explorer

Have you fixed this issue.If so please share the solution

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...