All Apps and Add-ons

Slack alert not sending?

nick405060
Motivator

Hi guys,

I have four Slack alerts that are not sending to their specified channels, but other of my Slack alerts are working. Why would this be?

0 Karma
1 Solution

nick405060
Motivator

Your message field cannot be empty. You must specify " " or put some other value in there for a message. This is either 1) a bug or 2) intended functionality, which makes no sense, because EVERY other Slack integration besides Splunk just lets you pump the data out directly. If 2) is indeed the case, and for some bizarre reason this is intended functionality, there should at least be an error message instead of just letting you save the alert which will be secretly not working.

View solution in original post

dajomas
Path Finder

@nick405060 Hi there,

unfortunately, I haven't been working with Splunk a lot and to my shame, the Slack alert app has been slipping a bit.

I will have to dig into the reason why I had the message field mandatory and if that's the case, why it doesn't warn when it is actually empty.

Might well be a bug. But I can't say right now.

I will keep you posted.

Best regards,
Johan

nick405060
Motivator

One other issue: the specified whitespace " " to fix this issue gets wiped on reboot. So the integrations get disabled upon reboot

0 Karma

nick405060
Motivator

Your message field cannot be empty. You must specify " " or put some other value in there for a message. This is either 1) a bug or 2) intended functionality, which makes no sense, because EVERY other Slack integration besides Splunk just lets you pump the data out directly. If 2) is indeed the case, and for some bizarre reason this is intended functionality, there should at least be an error message instead of just letting you save the alert which will be secretly not working.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...