<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for SolarWinds - Alerts input not working in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/584550#M11535</link>
    <description>&lt;P&gt;We resolved this issue ourselves.&amp;nbsp; &amp;nbsp; The needed Splunk logs&amp;nbsp; for each SolarWinds Alert can be found at $SPLUNK_HOME/var/log/splunk. When looking at the solarwinds_alerts log,&amp;nbsp; we noticed that the initial_start_time was set to the future --&amp;nbsp; it was set to&amp;nbsp;&lt;SPAN&gt;2022-02-28T00:00:00.0&amp;nbsp; instead of 2022-01-28T00:00:00.0.&amp;nbsp; We changed the&amp;nbsp; initial_start_time to&amp;nbsp;2022-01-28T00:00:00.0 in the GUI, restarted splunk, and tested again.&amp;nbsp; Still no alerts being generated.&amp;nbsp; &amp;nbsp;We then rebooted the server and the alerts were still not being generated after reboot.&amp;nbsp; &amp;nbsp;When we looked at the log file again it kept identifying the original&amp;nbsp; incorrect&amp;nbsp;initial_start_time in the log though it was displayed correctly with a time of&amp;nbsp;2022-01-28T00:00:00.0&amp;nbsp;&amp;nbsp;in the GUI.&amp;nbsp; &amp;nbsp;Finally, we created a new alert with the correct&amp;nbsp;initial_start_time of&amp;nbsp;2022-01-28T00:00:00.0 and everything worked.&amp;nbsp; &amp;nbsp;The original alert still does not work.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 15:46:22 GMT</pubDate>
    <dc:creator>Splunking</dc:creator>
    <dc:date>2022-02-10T15:46:22Z</dc:date>
    <item>
      <title>Splunk Add-on for SolarWinds - Alerts input not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/583599#M11424</link>
      <description>&lt;P&gt;We have a standalone Splunk Enterprise environment running Splunk 8.2.x.&amp;nbsp; &amp;nbsp;We have loaded the Splunk Add-on for SolarWinds&amp;nbsp; (latest version -- just downloaded it about two weeks ago).&amp;nbsp; &amp;nbsp; We are trying to get all three SolarWinds inputs (Alerts, Query, Inventory) to work in the Splunk Add-on for SolarWinds.&amp;nbsp; The Query and Inventory Inputs work fine but the Alerts are not working&amp;nbsp; (we are getting no data returned even though SolarWinds is producing alerts on its console).&amp;nbsp; My questions are these:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Has anyone else experienced this problem and found a solution?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Does anyone know which logs in either Splunk or SolarWinds that we can look at to help debug this issue?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 16:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/583599#M11424</guid>
      <dc:creator>Splunking</dc:creator>
      <dc:date>2022-02-03T16:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for SolarWinds - Alerts input not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/584550#M11535</link>
      <description>&lt;P&gt;We resolved this issue ourselves.&amp;nbsp; &amp;nbsp; The needed Splunk logs&amp;nbsp; for each SolarWinds Alert can be found at $SPLUNK_HOME/var/log/splunk. When looking at the solarwinds_alerts log,&amp;nbsp; we noticed that the initial_start_time was set to the future --&amp;nbsp; it was set to&amp;nbsp;&lt;SPAN&gt;2022-02-28T00:00:00.0&amp;nbsp; instead of 2022-01-28T00:00:00.0.&amp;nbsp; We changed the&amp;nbsp; initial_start_time to&amp;nbsp;2022-01-28T00:00:00.0 in the GUI, restarted splunk, and tested again.&amp;nbsp; Still no alerts being generated.&amp;nbsp; &amp;nbsp;We then rebooted the server and the alerts were still not being generated after reboot.&amp;nbsp; &amp;nbsp;When we looked at the log file again it kept identifying the original&amp;nbsp; incorrect&amp;nbsp;initial_start_time in the log though it was displayed correctly with a time of&amp;nbsp;2022-01-28T00:00:00.0&amp;nbsp;&amp;nbsp;in the GUI.&amp;nbsp; &amp;nbsp;Finally, we created a new alert with the correct&amp;nbsp;initial_start_time of&amp;nbsp;2022-01-28T00:00:00.0 and everything worked.&amp;nbsp; &amp;nbsp;The original alert still does not work.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 15:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/584550#M11535</guid>
      <dc:creator>Splunking</dc:creator>
      <dc:date>2022-02-10T15:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for SolarWinds - Alerts input not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/680870#M18886</link>
      <description>&lt;P&gt;Are you saying that the add-on is not worth using?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 20:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Add-on-for-SolarWinds-Alerts-input-not-working/m-p/680870#M18886</guid>
      <dc:creator>ilhwan</dc:creator>
      <dc:date>2024-03-15T20:16:15Z</dc:date>
    </item>
  </channel>
</rss>

