Alerting

webhook error

surekhasplunk
Communicator

Hi,

Alert is getting triggered, sendmail works fine but webhook not working. 

if i search index=_internal action=webhook

I see below error :

ERROR sendmodalert - action=webhook - Execution of alert action script failed

INFO sendmodalert - action=webhook STDERR - Sending POST request to url=http://XXXXXXXX/ with size=448 bytes payload

And in the splunkd.log i see below error :


07-15-2020 18:35:41.311 +0200 WARN ScriptRunner - Killing script, probably timed out, grace=5sec, script="bla/bla/splunk/etc/apps/alert_webhook/bin/webhook.py --execute"
07-15-2020 18:35:41.314 +0200 ERROR sendmodalert - action=webhook - Execution of alert action script failed
07-15-2020 18:35:41.314 +0200 ERROR sendmodalert - Error in 'sendalert' command: Alert script execution failed.
07-15-2020 18:35:41.314 +0200 ERROR SearchScheduler - Error in 'sendalert' command: Alert script execution failed., search='sendalert webhook results_file=

 

Do I have to pass the token also along with the url in the webhook configuration page ?

Currently in the triggeracgtion -> Webhook  -> url -> i have just added the client url like this : http://IPoftheclientmachine:port/

DO i have to append this with some token or something else at the end of the url ?

Labels (1)
Tags (2)
0 Karma

morethanyell
Builder

#metoo

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...