<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sendtophantom: Alert action script returned error code=1 in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/633820#M14864</link>
    <description>&lt;P&gt;Did you make it work? What was your issue?&lt;/P&gt;</description>
    <pubDate>Wed, 08 Mar 2023 23:03:32 GMT</pubDate>
    <dc:creator>freddy_Guo</dc:creator>
    <dc:date>2023-03-08T23:03:32Z</dc:date>
    <item>
      <title>How to resolve error: sendtophantom: Alert action script returned error code=1?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/619559#M14484</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently switched from Phantom to SOAR and I'm trying to send our triggered alerts to SOAR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tested that from Splunk Enterprise to SOAR connect and it works.&lt;/P&gt;
&lt;P&gt;But I keep getting the following error for one alert&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;11-04-2022 05:31:21.724 +1100 WARN  sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script returned error code=1

11-04-2022 05:31:21.724 +1100 INFO  sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script completed in duration=1394 ms with exit code=1&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 15:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/619559#M14484</guid>
      <dc:creator>freddy_Guo</dc:creator>
      <dc:date>2023-03-02T15:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: sendtophantom: Alert action script returned error code=1</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/632891#M14833</link>
      <description>&lt;P&gt;I'm also having the same error. How did you fix it?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;03-01&lt;/SPAN&gt;-2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;15:00:20.084&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0000&lt;/SPAN&gt; &lt;SPAN class=""&gt;WARN&lt;/SPAN&gt; &lt;SPAN class=""&gt;sendmodalert&lt;/SPAN&gt; [&lt;SPAN class=""&gt;36371&lt;/SPAN&gt; &lt;SPAN class=""&gt;AlertNotifierWorker-0&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;action=aws_sns_modular_alert&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alert&lt;/SPAN&gt; &lt;SPAN class=""&gt;action&lt;/SPAN&gt; &lt;SPAN class=""&gt;script&lt;/SPAN&gt; &lt;SPAN class=""&gt;returned&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;code=1&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Mar 2023 01:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/632891#M14833</guid>
      <dc:creator>splunkoptimus</dc:creator>
      <dc:date>2023-03-02T01:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: sendtophantom: Alert action script returned error code=1</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/632897#M14835</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244852"&gt;@splunkoptimus&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our issue was caused by a missing label. So we have label "threat" configured in Phantom but not in SOAR. So SOAR was throwing error due to no matching label found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully that helps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 02:38:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/632897#M14835</guid>
      <dc:creator>freddy_Guo</dc:creator>
      <dc:date>2023-03-02T02:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: sendtophantom: Alert action script returned error code=1</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/633820#M14864</link>
      <description>&lt;P&gt;Did you make it work? What was your issue?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 23:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/633820#M14864</guid>
      <dc:creator>freddy_Guo</dc:creator>
      <dc:date>2023-03-08T23:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: sendtophantom: Alert action script returned error code=1</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/633835#M14865</link>
      <description>&lt;P&gt;No, there were special characters in my lookup which caused the email alert_action python script to break. Once I removed the special characters email were sent out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 06:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-resolve-error-sendtophantom-Alert-action-script-returned/m-p/633835#M14865</guid>
      <dc:creator>splunkoptimus</dc:creator>
      <dc:date>2023-03-09T06:35:31Z</dc:date>
    </item>
  </channel>
</rss>

