All Apps and Add-ons

Slack Add on App

manish_singh_77
Builder

Hi Folks,

I am getting an error message when trying to send alerts from Splunk to Slack.

Here is an error message:

sendmodalert - action=slack_webhook_alert - Alert action script returned error code=255
ERROR SearchScheduler - Error in 'sendalert' command: Alert script returned error code 255., search='sendalert slack_webhook_alert results_file

Any idea, what must be causing this issue?

Tags (2)
0 Karma

rkyadav
Path Finder

You can check out two option :
1. Check the permissions on your stored credential objects. They must be shared either globally or within the slack_webhook_alert app.
2.checkpointer-from where you are trying to access

0 Karma

manish_singh_77
Builder

@rkyadav

I did not understand the second point, I also noticed that when configured the new webhook_name alerts are coming but not coming in the set duration.

For instance, if alert has been scheduled to run every 5 mins then in 30 mins, I am getting only 2 alerts.

0 Karma

rkyadav
Path Finder

Do you have issue with Error code=255 or scheduling an alert ?

Try changing the trigger action to "For each result"

0 Karma

manish_singh_77
Builder

@rkyadav

I have set the trigger action to once only.

0 Karma

manish_singh_77
Builder

@rkyadav

We don't have to trigger for each result as it will create unnecessary confusion for the users.

0 Karma

manish_singh_77
Builder

@rkyadav

I am majorly observing delay in the alerts on Slack channel.

0 Karma

rkyadav
Path Finder

check out your connectivity , seems like have an issue

0 Karma

rkyadav
Path Finder

Error 255 : This is usually happens when the remote is down/unavailable; or the remote machine doesn't have ssh installed; or a firewall doesn't allow a connection to be established to the remote host or could be your host key verification failed.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...