All Apps and Add-ons

Slack alert not sending?

nick405060
Motivator

Hi guys,

I have four Slack alerts that are not sending to their specified channels, but other of my Slack alerts are working. Why would this be?

0 Karma
1 Solution

nick405060
Motivator

Your message field cannot be empty. You must specify " " or put some other value in there for a message. This is either 1) a bug or 2) intended functionality, which makes no sense, because EVERY other Slack integration besides Splunk just lets you pump the data out directly. If 2) is indeed the case, and for some bizarre reason this is intended functionality, there should at least be an error message instead of just letting you save the alert which will be secretly not working.

View solution in original post

dajomas
Path Finder

@nick405060 Hi there,

unfortunately, I haven't been working with Splunk a lot and to my shame, the Slack alert app has been slipping a bit.

I will have to dig into the reason why I had the message field mandatory and if that's the case, why it doesn't warn when it is actually empty.

Might well be a bug. But I can't say right now.

I will keep you posted.

Best regards,
Johan

nick405060
Motivator

One other issue: the specified whitespace " " to fix this issue gets wiped on reboot. So the integrations get disabled upon reboot

0 Karma

nick405060
Motivator

Your message field cannot be empty. You must specify " " or put some other value in there for a message. This is either 1) a bug or 2) intended functionality, which makes no sense, because EVERY other Slack integration besides Splunk just lets you pump the data out directly. If 2) is indeed the case, and for some bizarre reason this is intended functionality, there should at least be an error message instead of just letting you save the alert which will be secretly not working.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...