The Telegram Alert Action allows Splunk to send alerts to Telegram groups and chats through the use of a Telegram Bot.
To install the Telegram Alert Action, follow the instructions in the Splunk Add-ons
1.) In the Search & Reporting app, run a search for your string.
2.) Confirm that the search results look as you expect.
3.) Click the Save As dropdown link above the right side of the search box, then select Alert from the menu that appears.
4.) Enter a title for your alert, along with a description if desired, and configure the standard alert fields related to permissions, scheduling, and trigger conditions according to your needs.
5.) Under Trigger Actions, click + Add Actions, then select Telegram Alert.
6.) Enter the Message and select the Severity that you want Telegram to send when the alert is triggered.
7.) Enter the Chat ID and the Bot ID that you will be sending the Alert, Message, and Result link to, then click Save.
1.) In the Search & Reporting app, navigate to the Alerts tab and locate the existing alert.
2.) Click Edit, then select Edit Actions.
3.) Click + Add Actions, then select Telegram Alert.
4.) Enter the Message and select the Severity that you want Telegram to send when the alert is triggered.
5.) Enter the Chat ID and the Bot ID that you will be sending the Alert, Message, and Result link to, then click Save.
For more information on the Telegram Bot API visit the Telegram Bot API website.
If you would like to contribute: https://github.com/ragedsparrow/splunk_telegram-alert-action
Implemented new logging.
Updated script to Python 3 compatible.
Enable Proxy settings.
Updating the meta files.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.