Alerting

Why is Microsoft Teams Card not displaying the alert body?

andrei_yay
New Member

Hi,

I'm trying to setup some alerts using the Microsoft Teams Card add-on. 

So I installed the add-on, created a Teams channel and defined an alert which should be sent via a webhook whenever it is triggered. The problem I noticed is that the alerts are sent when the conditions are met but I can see only the title and the subtitle of the alert, not also the actual message/body which should be a custom text containing a log line.

This si how i defined the alert :

andrei_yay_0-1649075587938.png

andrei_yay_1-1649075688085.png

This is how i receive the alerts in Teams :

andrei_yay_2-1649075749812.png

 

I can't figure out what i'm doing wrong. I mention i'm very new to Splunk.

Maybe the strcat function I use at the end of the query does not generate the apropriate output for the Teams add-on  ?

If i run the alert query in the "Search & Reporting" app i get good results: 


andrei_yay_3-1649076141034.png

 

 

 

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...