All Apps and Add-ons

Unable to install HTTP Alert Action in Splunk Cloud

jjsplunk
Engager

Hello,

I'm trying to install https://splunkbase.splunk.com/app/5022 in a Splunk Cloud instance.

If I download the app file and try to install it manually, I get this error:

"This app is available for installation directly from Splunkbase. To install this app, use App Browser page in Splunk Web"

In Splunk - Find more apps - I searched for HTTP, HTTP Alert, Brendan's name... and the app is not showing up.

Could anyone advise whether I'm doing something wrong or how I can get this app installed?

Thanks in advance

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @jjsplunk 

Unfortunately that app isnt Splunk Cloud compatible which is why its not showing in the App browser in Splunk Cloud.

You are also not able (as you have found) to upload an app with the same ID as an app in Splunkbase.

Under versions if an app is compatible then Splunk Cloud will be listed in addition to Splunk Enterprise.

livehybrid_0-1754581873389.png

I wouldnt necessarily recommend it due to support headaches, but I have known people to modify the ID of an app downloaded from Splunkbase (in the app.conf) and then upload it as a private app. I wouldnt attempt this if you are unfamiliar with building private apps for Splunk Cloud. As I said, this also introduces support headaches etc and will not be automatically updated. Theres also nothing to guarantee the app will pass Appinspect as a private app either.

 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

brendanmacooper
Explorer

Hi JJ,

 

Unfortunately the AppInspect team decided on a whim to fail the manual vetting for the latest version of this app. (it passed every version before, the reviewer was just having a bad day)

You have two options:

1. Upload as private app, to do this: change the appid in app.conf, rename the folder to match the new appid, gzip it up and upload as a private app.

Note: this is will break the connection to Splunkbase, you won't be able to automatically update the app from within Splunk.

2. Wait for me to upload a new version. Maybe the reviewer will be in a better mood.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @jjsplunk 

Unfortunately that app isnt Splunk Cloud compatible which is why its not showing in the App browser in Splunk Cloud.

You are also not able (as you have found) to upload an app with the same ID as an app in Splunkbase.

Under versions if an app is compatible then Splunk Cloud will be listed in addition to Splunk Enterprise.

livehybrid_0-1754581873389.png

I wouldnt necessarily recommend it due to support headaches, but I have known people to modify the ID of an app downloaded from Splunkbase (in the app.conf) and then upload it as a private app. I wouldnt attempt this if you are unfamiliar with building private apps for Splunk Cloud. As I said, this also introduces support headaches etc and will not be automatically updated. Theres also nothing to guarantee the app will pass Appinspect as a private app either.

 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...