All Apps and Add-ons

Slack Add on App

manish_singh_77
Builder

Hi Folks,

I am getting an error message when trying to send alerts from Splunk to Slack.

Here is an error message:

sendmodalert - action=slack_webhook_alert - Alert action script returned error code=255
ERROR SearchScheduler - Error in 'sendalert' command: Alert script returned error code 255., search='sendalert slack_webhook_alert results_file

Any idea, what must be causing this issue?

Tags (2)
0 Karma

rkyadav
Path Finder

You can check out two option :
1. Check the permissions on your stored credential objects. They must be shared either globally or within the slack_webhook_alert app.
2.checkpointer-from where you are trying to access

0 Karma

manish_singh_77
Builder

@rkyadav

I did not understand the second point, I also noticed that when configured the new webhook_name alerts are coming but not coming in the set duration.

For instance, if alert has been scheduled to run every 5 mins then in 30 mins, I am getting only 2 alerts.

0 Karma

rkyadav
Path Finder

Do you have issue with Error code=255 or scheduling an alert ?

Try changing the trigger action to "For each result"

0 Karma

manish_singh_77
Builder

@rkyadav

I have set the trigger action to once only.

0 Karma

manish_singh_77
Builder

@rkyadav

We don't have to trigger for each result as it will create unnecessary confusion for the users.

0 Karma

manish_singh_77
Builder

@rkyadav

I am majorly observing delay in the alerts on Slack channel.

0 Karma

rkyadav
Path Finder

check out your connectivity , seems like have an issue

0 Karma

rkyadav
Path Finder

Error 255 : This is usually happens when the remote is down/unavailable; or the remote machine doesn't have ssh installed; or a firewall doesn't allow a connection to be established to the remote host or could be your host key verification failed.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...