All Apps and Add-ons

How to deploy and configure the Slack Notification Alert app in a search head clustering environment?

randyszucs
Explorer

Installing the Slack Notification Alert app works fine when I install it as a stand alone, but my servers are clustered and the app doesn't work when pushed out with shcluster-bundle. I noticed that it takes the local directory and puts that into the default directory when deployed. The app will install, but will not let you add a Channel or Message when editing Trigger Actions. Is there a fix for this and does it work with clustered services?

Thank you,

cybersecnutant
Explorer

I'm having issues with the webhook URL not propagating in the cluster. Current version is 8.01 after having upgraded from 6.5 --> 7.0 --> 7.1.3 --> 8.01. 2 out of 5 of my searchheads have an empty field waiting for the webhook URL to be entered. The other 3 don't have a box.

0 Karma

pattokt
Explorer

What did you end up doing to fix your issue? I believe I could be running into the same.

Thanks

0 Karma

randyszucs
Explorer

Works in a clustered environment - issue with my shcluster-bundle push.

Get Updates on the Splunk Community!

Blueprints for High-Maturity Operations: Splunk Lantern Articles on SOAR, ES 8.4, ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...