<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Modify session key expiration time custom script alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Modify-session-key-expiration-time-custom-script-alert/m-p/412137#M7225</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;

&lt;P&gt;I have an alert that triggers a custom script (python), this script executes several validations on the data and creates a service using the passed session key to execute other 2 SPLs. &lt;BR /&gt;
At some point the session key is expiring and script fails to execute SPLs. &lt;/P&gt;

&lt;P&gt;I’m using  the deprecated functionality for custom alerts.&lt;/P&gt;

&lt;P&gt;Is there any way to increase the lifetime of the session key ? &lt;BR /&gt;
Do I need to move to the new custom alert framework to avoid this issue?&lt;/P&gt;

&lt;P&gt;I know I can move my code to a separate script that runs in a cron job outside splunk but then it’s more services to maintain plus having to use a username/password to create a splunk service.&lt;BR /&gt;
The actual process is very convenient in that sense. &lt;/P&gt;

&lt;P&gt;Thanks !&lt;/P&gt;</description>
    <pubDate>Sat, 20 Apr 2019 16:37:08 GMT</pubDate>
    <dc:creator>mgarciar</dc:creator>
    <dc:date>2019-04-20T16:37:08Z</dc:date>
    <item>
      <title>Modify session key expiration time custom script alert</title>
      <link>https://community.splunk.com/t5/Alerting/Modify-session-key-expiration-time-custom-script-alert/m-p/412137#M7225</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;

&lt;P&gt;I have an alert that triggers a custom script (python), this script executes several validations on the data and creates a service using the passed session key to execute other 2 SPLs. &lt;BR /&gt;
At some point the session key is expiring and script fails to execute SPLs. &lt;/P&gt;

&lt;P&gt;I’m using  the deprecated functionality for custom alerts.&lt;/P&gt;

&lt;P&gt;Is there any way to increase the lifetime of the session key ? &lt;BR /&gt;
Do I need to move to the new custom alert framework to avoid this issue?&lt;/P&gt;

&lt;P&gt;I know I can move my code to a separate script that runs in a cron job outside splunk but then it’s more services to maintain plus having to use a username/password to create a splunk service.&lt;BR /&gt;
The actual process is very convenient in that sense. &lt;/P&gt;

&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 16:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Modify-session-key-expiration-time-custom-script-alert/m-p/412137#M7225</guid>
      <dc:creator>mgarciar</dc:creator>
      <dc:date>2019-04-20T16:37:08Z</dc:date>
    </item>
  </channel>
</rss>

