Docs » Send alert notifications to third-party services using Splunk Observability Cloud » Send alert notifications to Microsoft Teams using Splunk Observability Cloud

Send alert notifications to Microsoft Teams using Splunk Observability Cloud πŸ”—

You can configure Splunk Observability Cloud to automatically send alert notifications to a Microsoft Teams channel when a detector alert condition is met and when the alert clears.

To send Splunk Observability Cloud alert notifications to Microsoft Teams, complete the following configuration tasks:

For troubleshooting information, see Troubleshooting Microsoft Teams.

Existing Office 365 integrations appear in Splunk Observability Cloud within the Microsoft Teams tile.

Step 1: Get the webhook URL for the Microsoft Team channel πŸ”—

You must be an owner or administrator of the Microsoft Team to complete this task.

To get the webhook URL for the Microsoft Team channel:

  1. Log in to Microsoft Teams and navigate to the list of teams.

  2. Select the team that contains the channel you want to send alert notifications to. Expand the list of channels.

  3. Find and hover over the channel you want to send alert notifications to. Select More options (…) and then select Connectors.

  4. Find the Incoming Webhook connector. Select Add. If the connector has already been added to the channel, select Configure.

  5. Enter a descriptive name for the connector.

  6. Select Create. Microsoft Teams generates a webhook URL.

  7. Select the Copy to Clipboard icon to copy the webhook URL for use in Step 2: Create a Microsoft Teams integration in Splunk Observability Cloud.

  8. Select Done.

Step 2: Create a Microsoft Teams integration in Splunk Observability Cloud πŸ”—

You must be a Splunk Observability Cloud administrator to complete this task.

To create a Microsoft Teams integration in Splunk Observability Cloud:

  1. Log in to Splunk Observability Cloud.

  2. Open the Microsoft Teams guided setup . Optionally, you can navigate to the guided setup on your own:

    1. In the left navigation menu, select Data Management.

    2. Go to the Available integrations tab, or select Add Integration in the Deployed integrations tab.

    3. In the integration filter menu, select All.

    4. In the Search field, search for Microsoft Teams, and select it.

    5. Select New Integration to display the configuration options.

  3. By default, the name of the integration is Microsoft Teams. Give your integration a unique and descriptive name. For information about the downstream use of this name, see About naming your integrations.

  4. In the Webhook URL field, paste the webhook URL you copied in Step 1: Get the webhook URL for the Microsoft Team channel. The webhook URL looks similar to this: https://<tenantName>.webhook.office.com/webhook2/<GroupExternalObjectGuid>@<TenantExternalGuid>/<ProviderName>/<AlternateGuid>/<GroupOwnerExternalObjectGuid>.

  5. Save.

  6. If Splunk Observability Cloud can validate the Microsoft Teams webhook URL, a Validated! success message displays. If an error displays instead, make sure that the webhook URL value you entered matches the value displayed in Microsoft Teams in Step 1: Get the webhook URL for the Microsoft Team channel.

Step 3: Add a Microsoft Teams integration as a detector alert recipient in Splunk Observability Cloud πŸ”—

To add a Microsoft Teams integration as a detector alert recipient in Splunk Observability Cloud:

  1. Create or edit a detector that you want to configure to send alert notifications using your Microsoft Teams integration.

    For more information about working with detectors, see Create detectors to trigger alerts and Subscribe to alerts using the Detector menu.

  2. In the Alert recipients step, select Add Recipient.

  3. Select Microsoft Teams and then select the name of the Microsoft Teams integration you want to use to sends alert notifications. This is the integration name you created in Step 2: Create a Microsoft Teams integration in Splunk Observability Cloud.

  4. Activate and save the detector.

Splunk Observability Cloud sends an alert notification to the Microsoft Teams channel when the detector triggers an alert and when the alert clears.

Troubleshoot your Microsoft Teams notification service integration πŸ”—

If the Microsoft Teams channel stops receiving notifications, consider the following troubleshooting tips:

  • Verify that the Microsoft Teams notification service integration in Splunk Observability Cloud still exists. To troubleshoot, complete the following steps. You must be a Splunk Observability Cloud administrator to complete these steps.

    1. In the Splunk Observability Cloud navigation menu, select Data Management > Deployed integrations.

    2. In the CATEGORIES menu, select Notification Services.

    3. Select the Microsoft Teams tile.

    4. Find your integration and select to expand it.

    5. Select the Integrations menu and select Validate. If you see an error message, Connector configuration not found, then the Incoming Webhook connector was removed from the Microsoft Teams channel and you must add it back. To do this, see Step 2: Create a Microsoft Teams integration in Splunk Observability Cloud.

  • Verify that the Microsoft Teams notification service integration in Splunk Observability Cloud has not been changed to send alert notifications to a different Microsoft Teams channel.

  • Verify that the Microsoft Teams notification service integration is still the alert recipient on the detector in Splunk Observability Cloud.

  • Verify that the Splunk Observability Cloud detector’s alert rules have not changed, causing it to send alert notifications for different reasons.