Alerting

alerts via health.conf

danman71
Loves-to-Learn Lots

Hey All, 

I have some questions about health.conf and web hooks. Recently I've been toying around with health.conf and testing some alerting. I noticed in my conf file I have alert_action.webhook. But I can't find anything in the documentation about it? What I would like to do is configure this to send an alert to a teams channel. Anyhow, if anyone has any information or done something similar, I'd like to hear about it. 

Labels (1)
0 Karma

danman71
Loves-to-Learn Lots

I have this app, and it works great when creating custom alerts. But I'm talking within the health.conf there is a webhooks stanza. I'm curious about that. Is a new feature, etc?

0 Karma

jodonald
Explorer

There is an app in Splunkbase which may help.  I would recommend starting there.

Hope that helps.

 

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...