Skip to main content

Webhook Connection for Microsoft Teams

thumbnail icon

Webhook connections rely on HTTP endpoints that tell Sumo Logic where to send data. You can set up any number of connections. 


See how to create an incoming webhook in Microsoft's documentation. Make sure that you copy and save the URL from Microsoft, you'll need to provide it to Sumo Logic in the URL input field when you create the Microsoft Teams Connection.

Configuration in Sumo Logic

In Sumo Logic, Scheduled Searches and Monitors send alerts to other tools via webhook connections. To send alerts from Sumo Logic to Microsoft Teams:

  1. Create a Microsoft Teams Connection.
  2. Use the Webhook Connection as the Alert Type in a Scheduled Search or the Connection Type in a Monitor.

Create a Microsoft Teams Connection


You need the Manage connections role capability to create webhook connections.

This section demonstrates how to create a webhook connection from Sumo Logic to Microsoft Teams.

  1. In the main Sumo Logic menu, select Manage Data > Monitoring > Connections.
  2. Click + Add and choose Microsoft Teams as the connection type.
    Microsoft Teams webhook connection tile.png
  3. Enter a Name and give an optional Description to the connection.
  4. Paste the URL from Microsoft Teams into the URL field.
  5. (Optional) Custom Headers, enter up to five comma separated key-value pairs.
  6. Customize the Activity Title if desired, the default is Monitor Alert: {{TriggerType}} on {{Name}}.
  7. (Optional) Customize the Activity Subtitle if desired, the default is Created On Date: {{TriggerTime}}.
  8. (Optional) Customize the Card Text if desired, the default is {{Description}}.

    Edits to the Activity TitleActivity Subtitle, and Card Text values are automatically updated in the JSON payload and vice versa.

  9. The following JSON is the default Alert Payload, which you can customize as needed. For details on variables you can use as parameters within your JSON object, see Webhook Payload Variables.
    "@type": "MessageCard",
    "@context": "",
    "themeColor": "#000099",
    "summary": "Monitor Alert: {{TriggerType}} on {{Name}}",
    "sections": [
    "activityTitle": "Monitor Alert: {{TriggerType}} on {{Name}}",
    "activitySubtitle": "Created On Date: {{TriggerTime}}",
    "activityImage": "",
    "text": "{{Description}}",
    "facts": [
    "name": "Monitor Query",
    "value": "{{Query}}"
    "name": "Trigger Condition",
    "value": "{{TriggerCondition}}"
    "name": "Trigger Value",
    "value": "{{TriggerValue}}"
    "name": "Trigger Time Range",
    "value": "{{TriggerTimeRange}}"
    "name": "Results",
    "value": "{{ResultsJson}}"
    "potentialAction": [
    "@type": "OpenUri",
    "name": "View Monitor Query",
    "targets": [
    "os": "default",
    "uri": "{{QueryURL}}"
  10. In the Recovery Payload section, you can customize your recovery notification.
  11. To test the connection, click Test Alert or Test Recovery. If successful, you'll see a 200 OK response message.
  12. Click Save.
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.