Alerting

I have an alert action that was created and it does not log any events to the cim_modactions index.

dsanders80
Loves-to-Learn Lots

I have an alert action that was created using the splunk add on builder in our test environment and it does not log any events to the cim_modactions index now that it is in production.  The SA_SPLUNK_CIM app is installed and the index is in splunk but it is empty.  I copied the SA_SPLUNK_CIM  app to our QA Environment and it logs events in the QA environment.  has anyone had an issue with the cim_modactions index not getting events logged to it?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...