All Apps and Add-ons

Slack Add on App

manish_singh_77
Builder

Hi Folks,

I am getting an error message when trying to send alerts from Splunk to Slack.

Here is an error message:

sendmodalert - action=slack_webhook_alert - Alert action script returned error code=255
ERROR SearchScheduler - Error in 'sendalert' command: Alert script returned error code 255., search='sendalert slack_webhook_alert results_file

Any idea, what must be causing this issue?

Tags (2)
0 Karma

rkyadav
Path Finder

You can check out two option :
1. Check the permissions on your stored credential objects. They must be shared either globally or within the slack_webhook_alert app.
2.checkpointer-from where you are trying to access

0 Karma

manish_singh_77
Builder

@rkyadav

I did not understand the second point, I also noticed that when configured the new webhook_name alerts are coming but not coming in the set duration.

For instance, if alert has been scheduled to run every 5 mins then in 30 mins, I am getting only 2 alerts.

0 Karma

rkyadav
Path Finder

Do you have issue with Error code=255 or scheduling an alert ?

Try changing the trigger action to "For each result"

0 Karma

manish_singh_77
Builder

@rkyadav

I have set the trigger action to once only.

0 Karma

manish_singh_77
Builder

@rkyadav

We don't have to trigger for each result as it will create unnecessary confusion for the users.

0 Karma

manish_singh_77
Builder

@rkyadav

I am majorly observing delay in the alerts on Slack channel.

0 Karma

rkyadav
Path Finder

check out your connectivity , seems like have an issue

0 Karma

rkyadav
Path Finder

Error 255 : This is usually happens when the remote is down/unavailable; or the remote machine doesn't have ssh installed; or a firewall doesn't allow a connection to be established to the remote host or could be your host key verification failed.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...