Splunk Line notify TA that is compatible with Splunk 8.x (origin from https://splunkbase.splunk.com/app/4614/)
To be used correctly, please ensure the Line Notify folder name is TA-line-notify-8-x
Method 1 - Using git clone
cd $SPLUNK_HOME/etc/apps
git clone https://github.com/dogqqq/TA-line-notify-8-x.git
- restart/start the Splunk
Method 2 - Download from github
- Download directly from github page
- Unzip the
.zip
file you just downloaded - Rename
TA-line-notify-8-x-main
toTA-line-notify-8-x
- Move the whole folder to
$SPLUNK_HOME/etc/apps/
- restart/start the Splunk
- When saving inline search to alert, choose Line Notify Alert
- Line token
- Must sign up and get
access token
from https://notify-bot.line.me/ first
- Must sign up and get
- Message kind
Raw
- Send event notify with _raw data
- Unnecessary to fill
Fields
Custom
- Send event notify with specific field
- Necessary to fill the
Fields