All Apps and Add-ons

Cannot Configure Slack Add on for Splunk 3.0

mhebert
New Member

When trying to configure the Slack Add on for Splunk 3.0 we keep getting an error in 'slack_audit_logs.py' : 'NoneType' object is not subscriptable

It looks like we can't subscribe the OAuth token. We're using Basic Authentication with an App and an OAuth token that's already working for the Slack Alerts app (so we know it works). When I place the OAuth token in the configuration, it tells me it's saved but after it's saved the field appears blank. Is that normal?

Also the Slack tema I'm working with says that they can't see any signs of the ap connecting or trying to connect to Slack. Googling it says that I have something misconfigured. I just can't figure out what.

Does anyone have any ideas as to what I'm doing wrong?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @mhebert 

Firstly, yes its normaly that a secret/password/token added in the Configuration page of the Splunk app would disappear when you go back to it - however if you re-submit the configuration without re-entering it then it may overwrite it to a blank value... Its no ideal but is what it is!

Regarding your oauth2 token, did you allow the required scopes from the docs at https://github.com/splunk/TA-slack-add-on-for-splunk/blob/master/README.md ?

In the app's settings, select OAuth & Permissions from the left navigation. Scroll down to the section titled Scopes.
Click Add an OAuth Scope under User Token Scopes. Add the auditlogs:read scope.
Click Add an OAuth Scope under Bot Token Scopes. Add the chat:write scope.
Scroll up to the OAuth Tokens section, click Install to Organization.
Click Allow in the pop-up window.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...