jacob-hudson / ProjectSASI

Splunk Alerts for Slack - Improved

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

ProjectSASI

Build Status

Splunk Alerts for Slack - Improved Includes:

  • Better formatting
  • Easy standardization
  • Automatic screenshots of visualizations

Requirements

  • Slack Webhook Token - For all standard alert features
  • Slack Bot User Token - For screenshots
  • Full Python 2.7 install (System Python can work) on the search head- For screenshots
  • Selenium via Pip (pip install selenium) on the sarach head- For screenshots
  • PhantomJS on the search head - For screenshots

Build

Pre-Built Packages

Manual Build

  • Download/Clone Repo (please ensure you are using a tagged commit)
  • Run ./build/build.sh

Install

  • Install From File in App Settings (App is not on SplunkBase yet)
  • NOTE: A restart is not needed after installing or upgrading this app

Example Output

Simple Alert

Example Slack Alerts

CSV File

Example Slack Alerts

Known Bugs

  • Dropdowns for Color and Emoji do not work (workaround: write in the color or emoji into the textbok for custom)

Find an issue?

  • Please report it here

About

Splunk Alerts for Slack - Improved

License:Apache License 2.0


Languages

Language:Python 60.5%Language:HTML 38.6%Language:Shell 0.9%