Why is Microsoft Teams Card not displaying the alert body?

New Member


I'm trying to setup some alerts using the Microsoft Teams Card add-on. 

So I installed the add-on, created a Teams channel and defined an alert which should be sent via a webhook whenever it is triggered. The problem I noticed is that the alerts are sent when the conditions are met but I can see only the title and the subtitle of the alert, not also the actual message/body which should be a custom text containing a log line.

This si how i defined the alert :



This is how i receive the alerts in Teams :



I can't figure out what i'm doing wrong. I mention i'm very new to Splunk.

Maybe the strcat function I use at the end of the query does not generate the apropriate output for the Teams add-on  ?

If i run the alert query in the "Search & Reporting" app i get good results: 





Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...