Alerting

Why are alerts not working after upgrade to Splunk 6.5.1?

levent_kurt
Explorer

Hi,

All of our alerts are not working after the upgrade to Splunk 6.5.1 from 6.3.0.

In the scheduler.log I have this error:

ERROR SavedSplunker - vector::_M_range_check: __n (which is 0) >= this->size() (which is 0)

Anyone else have this issue ?

Thanks !

Tags (1)

twinspop
Influencer

In our case it was a stats/chart command with a repeated field.

| stats last(fieldA) as fieldA ... last(fieldA) as fieldA

As soon as we removed the repeated fields, scheduling started firing.

0 Karma

ddrillic
Ultra Champion

An identical error message when upgrading to 6.5.0 -

ERROR SavedSplunker - vector::_M_range_check: __n (which is 0) >= this->size() (which is 0)

It's at Why are alerts not working after upgrade to Splunk 6.5.0?

@alewkowicz says -

alt text

0 Karma

levent_kurt
Explorer

I downvoted this post because the issue is with 6.5.1, not 6.5.0

0 Karma

ddrillic
Ultra Champion

You must be joking, right? ; -) it's the same issue and we are here to assist you at any time ....

0 Karma

levent_kurt
Explorer

Sorry for the confusion but we are using 6.5.1 version. @alewkowicz experienced this issue with 6.5.0 version Splunk support reported that it will be fixed in 6.5.1. Do you mean that the issue may not still be 6.5.1?

0 Karma

ddrillic
Ultra Champion

You see the issue, right? ; -) So, apparently, it's still there...

0 Karma

ddrillic
Ultra Champion

Splunk via @christopherr said the following in the other thread -

alt text

0 Karma

levent_kurt
Explorer

Reporter of the issue was using 6.5.0 but out version is 6.5.1, which this issue is supposed to be fixed.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...