All Apps and Add-ons

Microsoft Teams Webhook Alert Connector: Receiving "Error 400: Bad Request" after configuration. Has anyone been able to get this add-on to work?

ddavenpo
Explorer

Has anyone been able to get this to work? I just configured it. The configuration is crazy simple...but I am getting a 400 error:

ERROR sendmodalert - action=teams STDERR -  Error sending webhook request: HTTP Error 400: Bad Request
0 Karma
1 Solution

ddavenpo
Explorer

I figured out my issue. I was allowing the raw log to be passed to the alert. I think this was just too much information for the webhook receiver in Teams to handle. I changed my search to output a simple table with just a few values (which was what I actually wanted) and it worked just fine.

View solution in original post

ddavenpo
Explorer

I figured out my issue. I was allowing the raw log to be passed to the alert. I think this was just too much information for the webhook receiver in Teams to handle. I changed my search to output a simple table with just a few values (which was what I actually wanted) and it worked just fine.

cchimento
Path Finder

Hello - can you please post a search string example that you're sending to the alert and possible what your teams feed looks like when it receives that alert?

I am only getting one result from the table. Then a link to open in Splunk. I'd rather not.

So in short, I'm looking to expand and show more results in the Teams Feed.

0 Karma

ddavenpo
Explorer

I've tried removing the user agent component from the python script and that hasn't resolved the issue. I have successfully used the webhook URL in a simple curl command.

0 Karma

jesusreyes
New Member

Do you have any implementation guide for splunk with ms teams?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...