How it works...

This was a per-result type of alert, meaning that any time a 503 error event is seen, the alert is triggered and the webhook is triggered. In this example, we leveraged the webhook alert action capability of Splunk to make an HTTP POST request on a URL, resulting in a notification message being generated and displayed in a chat application. The webhook passes JSON formatted information about the alert in the body of the POST request.

For more information on using a webhook alert action, please see the Splunk documentation here: https://docs.splunk.com/Documentation/Splunk/latest/Alert/Webhooks.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.