<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log Event Alert Action not visible when creating alert in Security</title>
    <link>https://community.splunk.com/t5/Security/Log-Event-Alert-Action-not-visible-when-creating-alert/m-p/451128#M10540</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am creating an alert in an app which I have made using the add-on builder, my app name starts with SA-. As part of the alert I would like to use the log event trigger action. For some reason when I am in the context of my app I am unable to see this trigger action option. In the context of other apps such as search and other Splunk apps downloaded from splunk base I am able to see the log event trigger action.&lt;/P&gt;

&lt;P&gt;under settings&amp;gt;alert actions I have confirmed the log event alert action has been shared globally.&lt;BR /&gt;
Confirmed default.metadata in the alert_logevent app:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[alert_actions]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Confirmed my app is also shared globally.&lt;/P&gt;

&lt;P&gt;I've made the alert_logevent app visible which did not work.&lt;/P&gt;

&lt;P&gt;Tried renaming the app to remove the SA-&lt;/P&gt;

&lt;P&gt;If I go to settings&amp;gt;searches,report and alerts&amp;gt;new alert. Then create the alert from the context of my app, I am now able to see the alert action but when it runs I get the following error&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR SearchScheduler - Error in 'sendalert' command: Alert action "logevent" not found., search='sendalert logevent results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__nobody_U0EtZGFya21hdHRlci10aHJlYXQtZGV0ZWN0aW9u__6005_at_1565846400_1262_27223330-DB35-4A3A-8767-873F2404D37B/per_result_alert/tmp_5.csv.gz" results_link="https://splunkserver:8000/app/app_name/app_name?q=|loadjob scheduler__nobody_U0EtZGFya21hdHRlci10aHJlYXQtZGV0ZWN0aW9u__6005_at_1565846400_1262_27223330-DB35-4A3A-8767-873F2404D37B | head 6 | tail 1&amp;amp;earliest=0&amp;amp;latest=now"'
08-15-2019 09:20:02.390 +0400 INFO sendmodalert - Invoking modular alert action=logevent for search="6005" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I feel like it is a permission issue but not sure what else I can change.&lt;/P&gt;

&lt;P&gt;Splunk Enterprise V7.0 and also on V7.1.3&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2019 08:53:03 GMT</pubDate>
    <dc:creator>dsofoulis</dc:creator>
    <dc:date>2019-08-15T08:53:03Z</dc:date>
    <item>
      <title>Log Event Alert Action not visible when creating alert</title>
      <link>https://community.splunk.com/t5/Security/Log-Event-Alert-Action-not-visible-when-creating-alert/m-p/451128#M10540</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am creating an alert in an app which I have made using the add-on builder, my app name starts with SA-. As part of the alert I would like to use the log event trigger action. For some reason when I am in the context of my app I am unable to see this trigger action option. In the context of other apps such as search and other Splunk apps downloaded from splunk base I am able to see the log event trigger action.&lt;/P&gt;

&lt;P&gt;under settings&amp;gt;alert actions I have confirmed the log event alert action has been shared globally.&lt;BR /&gt;
Confirmed default.metadata in the alert_logevent app:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[alert_actions]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Confirmed my app is also shared globally.&lt;/P&gt;

&lt;P&gt;I've made the alert_logevent app visible which did not work.&lt;/P&gt;

&lt;P&gt;Tried renaming the app to remove the SA-&lt;/P&gt;

&lt;P&gt;If I go to settings&amp;gt;searches,report and alerts&amp;gt;new alert. Then create the alert from the context of my app, I am now able to see the alert action but when it runs I get the following error&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR SearchScheduler - Error in 'sendalert' command: Alert action "logevent" not found., search='sendalert logevent results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__nobody_U0EtZGFya21hdHRlci10aHJlYXQtZGV0ZWN0aW9u__6005_at_1565846400_1262_27223330-DB35-4A3A-8767-873F2404D37B/per_result_alert/tmp_5.csv.gz" results_link="https://splunkserver:8000/app/app_name/app_name?q=|loadjob scheduler__nobody_U0EtZGFya21hdHRlci10aHJlYXQtZGV0ZWN0aW9u__6005_at_1565846400_1262_27223330-DB35-4A3A-8767-873F2404D37B | head 6 | tail 1&amp;amp;earliest=0&amp;amp;latest=now"'
08-15-2019 09:20:02.390 +0400 INFO sendmodalert - Invoking modular alert action=logevent for search="6005" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I feel like it is a permission issue but not sure what else I can change.&lt;/P&gt;

&lt;P&gt;Splunk Enterprise V7.0 and also on V7.1.3&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 08:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-Event-Alert-Action-not-visible-when-creating-alert/m-p/451128#M10540</guid>
      <dc:creator>dsofoulis</dc:creator>
      <dc:date>2019-08-15T08:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log Event Alert Action not visible when creating alert</title>
      <link>https://community.splunk.com/t5/Security/Log-Event-Alert-Action-not-visible-when-creating-alert/m-p/451129#M10541</link>
      <description>&lt;P&gt;I've found the solution.&lt;BR /&gt;
To fix this I edited default.metadata&lt;BR /&gt;
[]&lt;BR /&gt;
import = app1, app2, alert_logevent&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 10:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-Event-Alert-Action-not-visible-when-creating-alert/m-p/451129#M10541</guid>
      <dc:creator>dsofoulis</dc:creator>
      <dc:date>2019-08-15T10:10:55Z</dc:date>
    </item>
  </channel>
</rss>

