Alerting

Alert Manager functionality not working in search head clsuter environment

sandyIscream
Communicator

We have implemented Alert manager in our prod environment.

The problem we are facing is that when we try to assign the alerts to a user in Splunk it is not working whereas when we try to do the same thing from the other search head it's getting assigned properly.

I checked the replication bundle status, artifacts count but didn't find any clue as to why this is happening.

Can someone explain as to why this is happening.

nawazns5038
Builder

Alert manager started working only after I changed the permissions of the alert to App rather than private.
Check permissions of the alerts

0 Karma

jkat54
SplunkTrust
SplunkTrust

Check for kvstore issues by searching

index=_internal sourcetype=mongod log_level=error

Correct any errors you see.

Also If you have a newer version of splunk there is a “Search Head Clustering” link in the settings drop down. It might have some clues too.

0 Karma

davpx
Communicator

You should ask simon@balz.me who created this.

0 Karma

sudosplunk
Motivator

Hello,

Not sure if you were able to fix this but are you using "Alert Manager" app from splunkbase? If yes, what is the version of the app?
Looks like the new version 2.2.2 has enhanced support for search head cluster.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...