So i have a search which show the indexes that have 0 events last 24hr. I want to send this result as an alert to microsoft teams from splunk . How can i do that i am using 9.1.4 version.
You can create incoming webhooks in teams and configure alert in Splunk and use webhook action under Trigger Actions or run a script to perform the same.
Refer below for creating incoming webhooks in Teams.
#https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/add-incomin...
Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
i am pasting the webhook url in the alert action nothing is happening.
From your Splunk server, test the webhook URL.
Eg: with curl,
curl -H 'Content-Type: application/json' -d '{"text":"Test message from Splunk"}' https://outlook.office.com/webhook/...
Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!