I've created a simple test search that looks at failed SSH logins for 'root' - This works fine when triggering on a realtime schedule, I've tested both Email and Send to Index which both work fine. However, it doesn't seem to work when selecting Webhook as the Alert Type.
I've created my webhook under data->settings->connections, and tested it there to confirm a HTTP 200 response is received. Checking the logs on the webserver show that no connection is being made at all from Sumo (aside from the test) , but I'm definitely seeing fresh results from that saved query.
Is there a way to further diagnose this?
Please sign in to leave a comment.