Custom alert action to send messages to Slack channels.
The account that owns the saved search needs the read_slack_alerts_credential capability, even
when the alert sets its own token or webhook URL override. admin and sc_admin already hold it.
Grant it to any other alert owner by either route:
- Add
read_slack_alerts_credential = enabledto a role the owner holds. - Assign the owner the shipped
slack_alert_actionrole.
Without it, the owner's alerts fail with exit code 7.
Splunk logs Alert action script returned error code=7 when the settings read fails. Search
slack_modalert.log for:
Slack settings broker call failed
Match its status against this table.
status |
Meaning | Fix |
|---|---|---|
0 |
No usable answer: refused connection, TLS failure, timeout, or unparsable body. | Run the following curl command to confirm splunkd answers. |
403 |
The owner lacks read_slack_alerts_credential, or SPLUNK_BINDIP in splunk-launch.conf binds splunkd to a routable address. |
Grant the capability. If an admin-owned alert also returns 403, the cause is SPLUNK_BINDIP. See Known issues in CHANGELOG.md. |
404 |
The app hasn't loaded since installation. | Restart splunkd. |
500 |
The endpoint failed to read the settings. | Read the error_type of the broker_failure entry with the same correlation_id in slack_alerts_credential_broker.log. |
On a Splunk Enterprise search head, reproduce a status with an account that holds the capability:
curl -sk -o /dev/null -w '%{http_code}\n' -u <user> \
"$(cat "$SPLUNK_HOME/var/run/splunk/splunkd_uri.txt")/services/slack_credential?output_mode=json"On Splunk Cloud Platform, run this search and read status from the result:
index=_internal source=*slack_modalert.log "Slack settings broker call failed"
- Search
slack_alerts_credential_broker.logfor abroker_stanza_unreadableentry, which names the stanza and anerror_type. - Set the Slack token or webhook URL on the Configuration tab.
See CHANGELOG.md for release notes and version history.