<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Script in App in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194386#M3366</link>
    <description>&lt;P&gt;well it's in the savedsearches.conf in the app folder, is that what you mean?&lt;/P&gt;</description>
    <pubDate>Wed, 19 Mar 2014 14:55:43 GMT</pubDate>
    <dc:creator>AlexMcDuffMille</dc:creator>
    <dc:date>2014-03-19T14:55:43Z</dc:date>
    <item>
      <title>Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194382#M3362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am currently able to successfully have a script execute after a search when located in $SPLUNK_HOME/bin/scripts.  However, I would like to have my scripts be separated by apps.  I have the script located now in $SPLUNK_HOME/etc/my_app_name/bin/scripts, but it doesn't work. &lt;/P&gt;

&lt;P&gt;I've also put it in $SPLUNK_HOME/etc/apps/my_app_name/bin/scripts and have not succeeded.&lt;/P&gt;

&lt;P&gt;Does anyone know how to get a script to work just in the context of an app?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194382#M3362</guid>
      <dc:creator>AlexMcDuffMille</dc:creator>
      <dc:date>2020-09-28T16:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194383#M3363</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
The directories are correct. Which OS and version of splunk are you using? Did you check if there is any dependency of path in the script itself? i have scripts running from the app itself. And Make sure the search also moved to the respective app. e.g. if you have your search is placed in search app it will be able to find it in global &lt;CODE&gt;bin/script&lt;/CODE&gt; directory but it won't look into your_app directory.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 13:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194383#M3363</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-03-19T13:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194384#M3364</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am running Splunk version 5.0.3, build 163460 on Ubuntu 12.04.2.  &lt;/P&gt;

&lt;P&gt;I do not see any dependency of the script itself.  It works fine when I put it in $SPLUNK_HOME/etc/my_app_name/bin/scripts&lt;/P&gt;

&lt;P&gt;I don't understand this, did you mean to say "script" instead of "search"?&lt;BR /&gt;
"And Make sure the search also moved to the respective app. e.g. if you have your search is placed in search app it will be able to find it in global bin/script directory but it won't look into your_app directory."&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194384#M3364</guid>
      <dc:creator>AlexMcDuffMille</dc:creator>
      <dc:date>2020-09-28T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194385#M3365</link>
      <description>&lt;P&gt;I meant the saved search which triggers the script should be present in the respective app folder rather than search app. Could you try that?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 14:45:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194385#M3365</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-03-19T14:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194386#M3366</link>
      <description>&lt;P&gt;well it's in the savedsearches.conf in the app folder, is that what you mean?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 14:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194386#M3366</guid>
      <dc:creator>AlexMcDuffMille</dc:creator>
      <dc:date>2014-03-19T14:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194387#M3367</link>
      <description>&lt;P&gt;yes it should work as expected then. Please go and check in the python.log in log folder what is the error you are getting when the search triggers the script?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 15:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194387#M3367</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-03-19T15:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Script in App</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194388#M3368</link>
      <description>&lt;P&gt;$SPLUNK_HOME/etc/apps/my_app_name/bin/scripts is the correct directory.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Script-in-App/m-p/194388#M3368</guid>
      <dc:creator>AlexMcDuffMille</dc:creator>
      <dc:date>2020-09-28T17:25:16Z</dc:date>
    </item>
  </channel>
</rss>

