All Apps and Add-ons

Is there a way to include a link to a dashboard in Slack Notification Alert?

mnm1987
Explorer

Hello Fellow Splunkers,
I have an Alert set up which sends notification into a Slack Channel, I wanted to know if there is a way to include links to a dashboard within the Slack Notification Alert Content.

Thanks.

0 Karma
1 Solution

richard_wilhite
Explorer

Would the alert point to many different dashboards, depending on the output? If they all point back to the same dashboard you can just use the dashboard link in plain text. Slack should auto format it as a link. The link will be something like https://splunk.mydomain.com/en-US/app/search/myDashboard

If you need different dashboards for different alert outcomes, you are probably going to need multiple alerts.

View solution in original post

richard_wilhite
Explorer

Would the alert point to many different dashboards, depending on the output? If they all point back to the same dashboard you can just use the dashboard link in plain text. Slack should auto format it as a link. The link will be something like https://splunk.mydomain.com/en-US/app/search/myDashboard

If you need different dashboards for different alert outcomes, you are probably going to need multiple alerts.

gjanders
SplunkTrust
SplunkTrust

Alternatively, if it's different dashboards based on the results of the search then you could use sendresults https://splunkbase.splunk.com/app/1794/ (or it may make more sense to have multiple alerts).

0 Karma

mnm1987
Explorer

Thanks for the response Richard. Each alert would point to the same dashboard but with different token inputs. I'll give it a shot.

0 Karma

richard_wilhite
Explorer

I just tested this with some form.field inputs and slack did format the link. I was able to click on it, and get the populated dashboard.
https://splunk.myDomain.com/en-US/app/search/myDashboard?form.field1=id&form.field1=displayName

You can, of course, also do form.field1=$result.foo$ to populate the dashboard with results from the search.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...