Getting Data In

Getting Microsoft Teams Data into Splunk?

tomapatan
Contributor

Hi,

I`m following this article in an attempt to ingest Teams data into Splunk and I need some help with testing the webhook - can someone confirm what the webhook URL is ?

 

 

 

 

curl WEBHOOK_ADDRESS -d '{"value": "test"}'

 

 

 

 

 

Also, looking at the documentation for the Teams Add-on for Splunk it states that "theTeams Webhook is not available for Splunk Cloud installations." - has anyone found an alternative solution for Cloud Deployments ?

We use Splunk in a hybrid (cloud + on prem) environment.

Many thanks.

Labels (1)
Tags (1)
1 Solution

tomapatan
Contributor
0 Karma

tomapatan
Contributor
0 Karma

tomapatan
Contributor

Thanks Paul,

The Microsoft Teams Add-on for Spunk includes a Microsoft Teams-specific webhook that I`ve configured, but the documentation (link above) does not include the webhook URL for me to test., which is what I`m after.

0 Karma

PaulPanther
Motivator

Okay, so you've  already defined a webhook address that is pointing directly to your data collection node or any load balancer, reverse proxy, or tunnel in front.

Then replace the WEBHOOK_ADDRESS placeholder with your defined webhook address and execute the curl command. 

The test is successful if your test event is searchable with 

sourcetype="m365:webhook"

 

0 Karma

tomapatan
Contributor

Hi Paul,

Unfortunately I didn`t get that far - when I created a new input in Splunk - add Teams Webhook, there`s no option to specify the URL, as per the screenshot attached. So I`m not sure where/how the webhook needs to be defined.

0 Karma

PaulPanther
Motivator

Ahh, got it. You have to define 3 different Inputs :

1. Create a Teams Webhook input

2. Create a Teams Subscription input

3. Create a Teams Call Record input

As described in the details of Microsoft Teams Add-on for Splunk | Splunkbase

In the Subscription input you can define the Webhook URL.

0 Karma

PaulPanther
Motivator

You must provide the webhook address that you wanna call from Microsoft Teams. How you do the configuration on Microsoft Teams is described here: Create and add an outgoing webhook in Teams - Microsoft Support

 

Regarding Splunk Cloud the documentation recommends Azure Function as an alternative:

Note: The Teams Webhook is not available for Splunk Cloud installations. Consider Azure Functions as an alternative.

Microsoft Teams Add-on for Splunk | Splunkbase

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...