Alerting

Issue in integrating Splunk alert with Slack

juhisaxena28
Explorer

We are trying to send data from Splunk to Slack via Trigger actions-- Add Actions method. Further we are entering the slack channel name and message. But we are not getting the alerts via slack. Please advise.

0 Karma

DavidHourani
Super Champion

Hi @juhisaxena28,

There are a lot of apps that allow you to send notifications and alerts to Slack. Personally I prefer this one :
https://splunkbase.splunk.com/app/2878/

Some description on how to use it can be found here:
https://answers.splunk.com/answers/351316/slack-notification-alert-how-can-i-get-the-message-1.html

you could also use this if you prefer, either works :
https://splunkbase.splunk.com/app/3525/

Cheers,
David

0 Karma

Vijeta
Influencer

@juhisaxena28 are you using Slack Webhook Alert TA? Have you configured the Account with Webhook name and URL?

0 Karma

juhisaxena28
Explorer

We are using Trigger actions option and selecting Slack dropdown as an option while editing the saved search.

0 Karma

Vijeta
Influencer

You might want to use Slack Webhook Alert add-on, once its configured correctly, you can select Slack webhook from Trigger actions dropdown in your saved search.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...