<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic alert manager script exit status 1 in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/alert-manager-script-exit-status-1/m-p/247174#M4619</link>
    <description>&lt;P&gt;Hi everyone, &lt;/P&gt;

&lt;P&gt;I have installed the alert manager on a single splunk instance (indexer/search head all together). &lt;BR /&gt;
I used the same procedure that I have been using to install it before: &lt;BR /&gt;
Install the add-on, install the app itself, copy and paste the alert_handler.py script under /alert_manager/bin/scripts. &lt;BR /&gt;
I didn't create a sym link, because when I did it, splunk couldn't find my script. &lt;/P&gt;

&lt;P&gt;The alert manager is actual running properly, but I can't manipulate the fields of the incident on the incident settings. &lt;BR /&gt;
I can' because the search on the incident_settings page doesn't produce any results, so basically my file :  inputlookup incident_settings doesn't exist. &lt;BR /&gt;
Splunk is running as root, the permission of all my apps, searches, everything are global. I m also able to query my kv stores, I checked with all the other lookup files that the alert manager creates.&lt;BR /&gt;
Checking on splunkd.log I got this error: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   11-27-2015 11:23:07.217 +0000 ERROR script - sid:scheduler__admin_aW50ZWdyaXR5LXNpZW0__RMD5ffc946a04a0b88fb_at_1448623380_16769 command="runshellscript", Script: /opt/splunk/bin/scripts/alert_handler.py exited with status code: 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That's, I guess, is the reason why I'm not able to write on the incident_results lookup. &lt;BR /&gt;
Could please someone helps me to solve this issue? I think is only related to the script. &lt;/P&gt;

&lt;P&gt;Thanks a million. &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:58:44 GMT</pubDate>
    <dc:creator>Federica_92</dc:creator>
    <dc:date>2020-09-29T07:58:44Z</dc:date>
    <item>
      <title>alert manager script exit status 1</title>
      <link>https://community.splunk.com/t5/Alerting/alert-manager-script-exit-status-1/m-p/247174#M4619</link>
      <description>&lt;P&gt;Hi everyone, &lt;/P&gt;

&lt;P&gt;I have installed the alert manager on a single splunk instance (indexer/search head all together). &lt;BR /&gt;
I used the same procedure that I have been using to install it before: &lt;BR /&gt;
Install the add-on, install the app itself, copy and paste the alert_handler.py script under /alert_manager/bin/scripts. &lt;BR /&gt;
I didn't create a sym link, because when I did it, splunk couldn't find my script. &lt;/P&gt;

&lt;P&gt;The alert manager is actual running properly, but I can't manipulate the fields of the incident on the incident settings. &lt;BR /&gt;
I can' because the search on the incident_settings page doesn't produce any results, so basically my file :  inputlookup incident_settings doesn't exist. &lt;BR /&gt;
Splunk is running as root, the permission of all my apps, searches, everything are global. I m also able to query my kv stores, I checked with all the other lookup files that the alert manager creates.&lt;BR /&gt;
Checking on splunkd.log I got this error: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   11-27-2015 11:23:07.217 +0000 ERROR script - sid:scheduler__admin_aW50ZWdyaXR5LXNpZW0__RMD5ffc946a04a0b88fb_at_1448623380_16769 command="runshellscript", Script: /opt/splunk/bin/scripts/alert_handler.py exited with status code: 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That's, I guess, is the reason why I'm not able to write on the incident_results lookup. &lt;BR /&gt;
Could please someone helps me to solve this issue? I think is only related to the script. &lt;/P&gt;

&lt;P&gt;Thanks a million. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-manager-script-exit-status-1/m-p/247174#M4619</guid>
      <dc:creator>Federica_92</dc:creator>
      <dc:date>2020-09-29T07:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: alert manager script exit status 1</title>
      <link>https://community.splunk.com/t5/Alerting/alert-manager-script-exit-status-1/m-p/247175#M4620</link>
      <description>&lt;P&gt;Ok, I found a solution. &lt;BR /&gt;
The problem wasn't the script but the incident settings page, basically I copied the xml code from an older version of the alert manager in the new one and it's working fine : ) &lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 13:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/alert-manager-script-exit-status-1/m-p/247175#M4620</guid>
      <dc:creator>Federica_92</dc:creator>
      <dc:date>2015-11-27T13:02:11Z</dc:date>
    </item>
  </channel>
</rss>

