Alerting

How to resolve error: sendtophantom: Alert action script returned error code=1?

freddy_Guo
Path Finder

Hi, 

We have recently switched from Phantom to SOAR and I'm trying to send our triggered alerts to SOAR. 

I have tested that from Splunk Enterprise to SOAR connect and it works.

But I keep getting the following error for one alert

 

 

 

11-04-2022 05:31:21.724 +1100 WARN  sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script returned error code=1

11-04-2022 05:31:21.724 +1100 INFO  sendmodalert [17285 AlertNotifierWorker-0] - action=sendtophantom - Alert action script completed in duration=1394 ms with exit code=1

 

 

 

 

Labels (1)
Tags (3)
0 Karma

splunkoptimus
Path Finder

I'm also having the same error. How did you fix it?

03-01-2023 15:00:20.084 +0000 WARN sendmodalert [36371 AlertNotifierWorker-0] - action=aws_sns_modular_alert - Alert action script returned error code=1
0 Karma

freddy_Guo
Path Finder

Did you make it work? What was your issue?

0 Karma

freddy_Guo
Path Finder

Hi @splunkoptimus,

 

Our issue was caused by a missing label. So we have label "threat" configured in Phantom but not in SOAR. So SOAR was throwing error due to no matching label found. 

Hopefully that helps. 

 

 

0 Karma

splunkoptimus
Path Finder

No, there were special characters in my lookup which caused the email alert_action python script to break. Once I removed the special characters email were sent out. 

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...