Repository navigation
Expand file tree
/
Copy pathglobalConfig.json
More file actions
157 lines (157 loc) · 6.44 KB
/
Copy pathglobalConfig.json
File metadata and controls
157 lines (157 loc) · 6.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
{
"meta": {
"name": "slack_alerts",
"displayName": "Slack Alerts",
"restRoot": "slack_alerts",
"version": "3.1.0",
"schemaVersion": "0.0.10",
"supportedThemes": [
"light",
"dark"
],
"supportedPythonVersion": [
"3.9",
"3.13"
]
},
"pages": {
"configuration": {
"title": "Configuration",
"description": "Set the default Slack credentials and options used by the Slack alert action.",
"tabs": [
{
"name": "settings",
"title": "Settings",
"entity": [
{
"type": "text",
"label": "Slack App OAuth Token",
"field": "slack_app_oauth_token",
"encrypted": true,
"required": false,
"help": "Default Slack App OAuth token (starts with xoxb-). Grant the chat:write and chat:write.public scopes. Preferred over the deprecated webhook URL.",
"options": {
"display": true
}
},
{
"type": "text",
"label": "Webhook URL",
"field": "webhook_url",
"encrypted": true,
"required": false,
"help": "Deprecated. Default Slack incoming webhook URL (must use HTTPS). Only used when no OAuth token is configured.",
"validators": [
{
"type": "regex",
"pattern": "^$|^https://.+",
"errorMsg": "Webhook URL must start with https://"
}
]
},
{
"type": "text",
"label": "From user",
"field": "from_user",
"required": false,
"defaultValue": "Splunk",
"help": "Username shown as the message sender. Webhook only; ignored when a Slack App OAuth token is set."
},
{
"type": "text",
"label": "From user icon",
"field": "from_user_icon",
"required": false,
"defaultValue": "https://s3-us-west-1.amazonaws.com/ziegfried-apps/slack-alerts/splunk-icon.png",
"help": "URL of the icon shown next to the message sender. Webhook only; ignored when a Slack App OAuth token is set."
}
]
},
{
"type": "proxyTab",
"name": "proxy"
},
{
"type": "loggingTab"
}
]
}
},
"alerts": [
{
"name": "slack",
"label": "Slack",
"description": "Send a message to a Slack channel",
"iconFileName": "slack.png",
"customScript": "slack_logic",
"entity": [
{
"type": "text",
"label": "Channel",
"field": "channel",
"required": false,
"help": "Slack channel to send the message to (should start with # or @). Leave empty to use the webhook default."
},
{
"type": "textarea",
"label": "Message",
"field": "message",
"required": true,
"help": "Chat message to send to the Slack channel. Can include tokens that insert text from the search results."
},
{
"type": "singleSelect",
"label": "Attachment",
"field": "attachment",
"required": false,
"defaultValue": "none",
"help": "Optionally include an attachment.",
"options": {
"items": [
{
"value": "none",
"label": "None"
},
{
"value": "alert_link",
"label": "Link to alert"
},
{
"value": "message",
"label": "Show message in attachment (instead of plain message)"
}
]
}
},
{
"type": "text",
"label": "Fields",
"field": "fields",
"required": false,
"help": "Show one or more fields from the search results below the Slack message. Comma-separated list of field names. Allows wildcards, e.g. index,source*."
},
{
"type": "text",
"label": "Slack App OAuth Token override",
"field": "slack_app_oauth_token_override",
"required": false,
"help": "Override the default Slack App OAuth token for this alert (e.g. to post to a different workspace)."
},
{
"type": "text",
"label": "Proxy URL override",
"field": "proxy_url_override",
"required": false,
"help": "Override the default proxy for this alert. Use http://yourproxy:port."
},
{
"type": "text",
"label": "Webhook URL override",
"field": "webhook_url_override",
"required": false,
"help": "Override the default Slack webhook URL for this alert."
}
]
}
]
}