Hi,
we are currently experiencing reliability issues when using the Microsoft Teams Add-on for Splunk (https://splunkbase.splunk.com/app/4994😞
Has anyone experienced similar issue and has a solution to this problem?
Hi,
I got the same issue.
I wrote a small patch for the teams_subscription.py binary to solve it.
It is based on release 2.0.0.
The patch is attached as TA_MS_Teams-bruno.patch.txt.
To use it, just save the file as TA_MS_Teams-bruno.patch in the $SPLUNK_HOME/etc/apps directory and apply it using the following command in the TA_MS_Teams directory:
pelai@xps MINGW64 /d/src/TA_MS_Teams
$ patch -p1 < ../TA_MS_Teams-bruno.patch.txt
patching file bin/teams_subscription.py
pelai@xps MINGW64 /d/src/TA_MS_Teams
$
It is possible to revert the patch at anytime just using patch with the -R parameter.
I hope this can help.
B.
For issue 1 I have also had this problem, where the subscription just stops working and does not auto-correct.
There is a lookup in the Splunk Enterprise instance which contains subscription information. You can make a scheduled search to overwrite this lookup, and then the app will make a new subscription and the logs should come in again.