Alerting

Why receiving error trying to push alerts into Swimlane using the Swimlane add-on?

srikaanth_amrut
New Member

Hello!

I'm trying to push alerts into Swimlane using the swimlane add-on. I've given full global permissions to the saved alert. There are 101 events to push but aren't getting pushed into Swimlane.

Please find logs below - 

04-13-202210:50:57.393 +0200ERRORSearchScheduler - Error in 'sendalert' command:Alert script returned error code 1., search='sendalertpush_alerts_to_swimlaneresults_file="/opt/splunk/var/run/splunk/dispatch/scheduler_c3Jpa2FhbnRoLmFtcnV0aGEub3B0aXY_emZfY29ycmVsYXRpb25zX2ZpcmVleWU__RMD58b260abcef59878b_at_1649839800_2808/per_result_alert/tmp_16.csv.gz" results_link="https://mycompanyabcd.com/app/xxx_correlations_fireeye/search?q=%7Cloadjob%20scheduler_c3Jpa2FhbnRoLmFtcnV0aGEub3B0aXY_emZfY29ycmVsYXRpb25zX2ZpcmVleWU__RMD58b260abcef59878b_at_1649839800_2808%20%7C%20head%2017%20%7C%20tail%201&earliest=0&latest=now "'


04-13-202210:50:57.393 +0200WARN sendmodalert - action=push_alerts_to_swimlane- Alert action script returnederrorcode=1

 

alert_screenshot.png

 

Any advise appreciated. Thanks!

Labels (2)
Tags (2)
0 Karma

Anji_splunk
Observer

Hi @srikaanth_amrut ,

Were you able to resolve this issue? Please share the solution, I am facing same issue.

Thank you

0 Karma