Alerting

I have an alert action that was created and it does not log any events to the cim_modactions index.

dsanders80
Loves-to-Learn Lots

I have an alert action that was created using the splunk add on builder in our test environment and it does not log any events to the cim_modactions index now that it is in production.  The SA_SPLUNK_CIM app is installed and the index is in splunk but it is empty.  I copied the SA_SPLUNK_CIM  app to our QA Environment and it logs events in the QA environment.  has anyone had an issue with the cim_modactions index not getting events logged to it?

Labels (1)
0 Karma