<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk stop runing the alert script after a few days, despite that the search trigger works! in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232090#M12041</link>
    <description>&lt;P&gt;I've hit a similar issue to the one you mention in an older Splunk version, re-creating the alert again (with identical configuration) fixed the issue, also upgrading to the current Splunk release (6.5.1) has not resulted in a re-occurence of the issue.&lt;/P&gt;

&lt;P&gt;In my case the alert script failed to fire sometimes, even though the alert itself fired, it's not a common problem so it may or may not be the same as the issue you are describing...just a potential answer.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2017 08:04:00 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2017-01-20T08:04:00Z</dc:date>
    <item>
      <title>Splunk stop runing the alert script after a few days, despite that the search trigger works!</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232087#M12038</link>
      <description>&lt;P&gt;Hi all, &lt;BR /&gt;
I have deployment environment with:&lt;BR /&gt;
5 search heads, 3 Indexers, 2 Heavy forwarders and 1 cluster master.&lt;/P&gt;

&lt;P&gt;I created the alert on one of the search head with "Cron schedule" and "Run a script" action.&lt;BR /&gt;
The problem begins after a few days when suddenly the script doesn't run!&lt;/P&gt;

&lt;P&gt;What checked: &lt;BR /&gt;
1. search lookup who trigger the script does work.&lt;BR /&gt;
2. index=_internal sourcetype="splunk_python" | search "my_script_name" - Does not appear!&lt;BR /&gt;
Splunk stop running the script after a few days, despite that the search trigger works!&lt;BR /&gt;
Any insight? What steps do we need to take to the run a script function work in such deployment environment ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232087#M12038</guid>
      <dc:creator>bugnet</dc:creator>
      <dc:date>2020-09-29T12:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stop runing the alert script after a few days, despite that the search trigger works!</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232088#M12039</link>
      <description>&lt;P&gt;Okay, so if the script worked for a few days, then stopped working, I'd start out by checking whether the components (bin etc) were all in place.  &lt;/P&gt;

&lt;P&gt;There are lots of production environments where the security team will UNDO work which has not been properly documented, without giving notice.  There are also lots of pseudo-production environments where people muck with each other's code, also without giving notice.  &lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 15:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232088#M12039</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-18T15:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stop runing the alert script after a few days, despite that the search trigger works!</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232089#M12040</link>
      <description>&lt;P&gt;Thanks. all components are in place.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2017 09:30:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232089#M12040</guid>
      <dc:creator>bugnet</dc:creator>
      <dc:date>2017-01-19T09:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stop runing the alert script after a few days, despite that the search trigger works!</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232090#M12041</link>
      <description>&lt;P&gt;I've hit a similar issue to the one you mention in an older Splunk version, re-creating the alert again (with identical configuration) fixed the issue, also upgrading to the current Splunk release (6.5.1) has not resulted in a re-occurence of the issue.&lt;/P&gt;

&lt;P&gt;In my case the alert script failed to fire sometimes, even though the alert itself fired, it's not a common problem so it may or may not be the same as the issue you are describing...just a potential answer.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 08:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232090#M12041</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-01-20T08:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stop runing the alert script after a few days, despite that the search trigger works!</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232091#M12042</link>
      <description>&lt;P&gt;check the expiry option &lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 06:16:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-stop-runing-the-alert-script-after-a-few-days-despite/m-p/232091#M12042</guid>
      <dc:creator>puneethgowda</dc:creator>
      <dc:date>2017-03-06T06:16:55Z</dc:date>
    </item>
  </channel>
</rss>

