Getting ready

To step through this recipe, you will need a running Splunk Enterprise server, with the sample data loaded from Chapter 1, Play Time - Getting Data In. You should be familiar with navigating the Splunk user interface.

Before you can use Splunk's webhook alert action, you will need to configure the app or server that will be receiving the alert, so that it is able to accept a JSON formatted POST. Many common web applications provide guided mechanisms for doing this. For example, in Slack you must add their incoming-webhook custom integration to your channel.

In addition, for those using Slack, this recipe leverages the Slack Notification Alert app available from Splunk Base here: https://splunkbase.splunk.com/app/2878/. This ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.