<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I setup an alert action for sending an email (App certification) in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300034#M5417</link>
    <description>&lt;P&gt;Hello,  &lt;/P&gt;

&lt;P&gt;Do you have any alert_actions.conf file in your app?  I think Splunk is assuming one be placed in the "default" directory of your app and another in the "local" directory of your app.&lt;BR /&gt;&lt;BR /&gt;
You also will need a savedsearch.conf file in the local directory of your app that describes the saved search and the action, e.g. email.&lt;BR /&gt;&lt;BR /&gt;
Test the saved search/alert BEFORE you package the app, it should work. &lt;BR /&gt;
Can you please post your savedsearch.conf stanza and alerts_actions.conf file to this posting? &lt;/P&gt;

&lt;P&gt;For more information about alert_actions.conf and alerts in general, please review these links,  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Alert/Aboutalerts" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/Alert/Aboutalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Feel free to post more. &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:31:01 GMT</pubDate>
    <dc:creator>pretzel2</dc:creator>
    <dc:date>2020-09-29T13:31:01Z</dc:date>
    <item>
      <title>How do I setup an alert action for sending an email (App certification)</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300033#M5416</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;BR /&gt;
I am attempting to package my app for Splunk app certification. In app inspect it keeps failing on alert_actions.conf.&lt;BR /&gt;
All I am trying to do is package up an action to send an email if a saved search has a number of results greater than one.&lt;/P&gt;

&lt;P&gt;These are the app inspect errors I get.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Alert actions structure and standards
    Check that each custom alert action has a valid executable.
        FAILURE: No executable was found for alert action email
        FAILURE: No executable was found for alert action custom_action
    Check that icon files defined for alert actions in alert_actions.conf
    exist. Custom Alert Action Component Reference
        FAILURE: No icon_path was specified for [email].
        FAILURE: No icon_path was specified for [custom_action].
    Check that custom alert actions are user configurable with setup.xml
    file.
        MANUAL_CHECK: An setup.xml exists at default/setup.xml.
    Check that each custom alert action has an associated html file.
        FAILURE: No HTML file was found at default/data/ui/alerts/ for
            /tmp/tmp5jtSeN/optiv_threat_intel/default/data/ui/alerts/email.html
        FAILURE: No HTML file was found at default/data/ui/alerts/ for
            /tmp/tmp5jtSeN/optiv_threat_intel/default/data/ui/alerts/custom_action.html
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I can't find any useful documentation that walks through this using alert actions. Do I need to have an executable script now? Again, all I want to do is send an email using internal spunk email functionality.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2017 20:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300033#M5416</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2017-04-02T20:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I setup an alert action for sending an email (App certification)</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300034#M5417</link>
      <description>&lt;P&gt;Hello,  &lt;/P&gt;

&lt;P&gt;Do you have any alert_actions.conf file in your app?  I think Splunk is assuming one be placed in the "default" directory of your app and another in the "local" directory of your app.&lt;BR /&gt;&lt;BR /&gt;
You also will need a savedsearch.conf file in the local directory of your app that describes the saved search and the action, e.g. email.&lt;BR /&gt;&lt;BR /&gt;
Test the saved search/alert BEFORE you package the app, it should work. &lt;BR /&gt;
Can you please post your savedsearch.conf stanza and alerts_actions.conf file to this posting? &lt;/P&gt;

&lt;P&gt;For more information about alert_actions.conf and alerts in general, please review these links,  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Alert/Setupalertactions&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Alert/Aboutalerts" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/Alert/Aboutalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Feel free to post more. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300034#M5417</guid>
      <dc:creator>pretzel2</dc:creator>
      <dc:date>2020-09-29T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I setup an alert action for sending an email (App certification)</title>
      <link>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300035#M5418</link>
      <description>&lt;P&gt;I did not find a resolution to this, so as a work around to push through the app certification process I commented out all the references to email alerts and actions.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2017 16:14:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-do-I-setup-an-alert-action-for-sending-an-email-App/m-p/300035#M5418</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2017-04-16T16:14:46Z</dc:date>
    </item>
  </channel>
</rss>

