Splunk Search

Strange message for SMS Alert

qiaojing
Path Finder

Hi, I'm currently trying to implement SMS Alert for Splunk. I have a SMS Gateway server in my organisation and I'm using it to send SMS alert.

I'm able to receive the SMS but the message was a long strange of nonsensical alphabets.

May I know if there's any formatting of the Splunk Alert that led to this? Or how can I configure the message such that the message sent via SMS is in human readable format.

Any help or idea will be greatly appreciated. Thank you 🙂

Tags (1)
0 Karma

newbie2tech
Communicator

@qiaojing did you get this working...if so can you share how

0 Karma

Jeremiah
Motivator

You might want to take a look at this answer:

https://answers.splunk.com/answers/140254/how-to-set-alert-emails-to-send-in-plain-text-in-splunk-6....

We actually saw a similar problem with sending emails directly from Splunk to our pager gateway. Now we aggregate alerts in our event management tool, and send the pages from there.

0 Karma

acharlieh
Influencer

If I had to guess it sounds like a character encoding problem somewhere along the line, whether that's whatever modular alert you're using with Splunk or the SMS Gateway.

0 Karma

qiaojing
Path Finder

@woodcook Hi thanks for your answer. We're suspecting it's some encoding issues as well but not very sure how to solve it. The server is an internal organisation server.

I created a very simple alert base search | stats count by NRIC | where count>0 on Splunk Enterprise.
I did not check any of the details included in the alert eg trigger time/condition. The subject & message is also kept to very simple without the email tokens.

Is there any way to strip all the encoding when splunk passes out the message?

Thank you.

0 Karma

qiaojing
Path Finder

Hi thanks for your answer. We're suspecting it's some encoding issues as well but not very sure how to solve it.

I created a very simple alert base search | stats count by NRIC | where count>0 on Splunk Enterprise.
I did not include any of the details in the alert eg trigger time/condition. The subject & message is also kept to very simple without the email tokens.

Is there any way to strip all the encoding when splunk passes out the message?

Thank you.

0 Karma

qiaojing
Path Finder

@acharlieh Hi thanks for your answer. We're suspecting it's some encoding issues as well but not very sure how to solve it.

I created a very simple alert base search | stats count by NRIC | where count>0 on Splunk Enterprise.
I did not include any of the details in the alert eg trigger time/condition. The subject & message is also kept to very simple without the email tokens.

Is there any way to strip all the encoding when splunk passes out the message?

Thank you.

0 Karma

woodcock
Esteemed Legend

Your joking, right? What are the details of your server? How are you alerting to it (slunkbase app, custom command, modular alert)? What are the details here?

0 Karma

qiaojing
Path Finder

Hi thanks for your answer. We're suspecting it's some encoding issues as well but not very sure how to solve it. The server is an internal organisation server.

I created a very simple alert base search | stats count by NRIC | where count>0 on Splunk Enterprise.
I did not check any of the details included in the alert eg trigger time/condition. The subject & message is also kept to very simple without the email tokens.

Is there any way to strip all the encoding when splunk passes out the message?

Thank you.

0 Karma

woodcock
Esteemed Legend

Are you SENDING an SMS or are you indexing SMS text into Splunk? If the former, how are you doing this (sending SMS is not a native Splunk capability). These are ABSOLUTELY CRITICAL details which you have not shared.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...