Alerting

Is the alert script capability for alert actions restricted to the admin user or is there a setting I can change?

pduflot
Path Finder

Hello,

I have a python script as an alert action.
I could not make it work until I changed the owner of the alert to admin. Even when the owner had the admin role, the script was not called.
In the scheduler.log, I see alert_actions="" when the user is not the admin user.
While I see, alert_actions="script" when the user is the admin user.

Is this alert script capability restricted to the admin user or are there any other settings I can change?

Thanks,

0 Karma
1 Solution

pduflot
Path Finder

Sorry I had one conflicted line remaining in the first alarm (alert_condition = search count = 1). User rights had nothing to do with it.

View solution in original post

0 Karma

pduflot
Path Finder

Sorry I had one conflicted line remaining in the first alarm (alert_condition = search count = 1). User rights had nothing to do with it.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...