Alerting

alert manager script exit status 1

Federica_92
Communicator

Hi everyone,

I have installed the alert manager on a single splunk instance (indexer/search head all together).
I used the same procedure that I have been using to install it before:
Install the add-on, install the app itself, copy and paste the alert_handler.py script under /alert_manager/bin/scripts.
I didn't create a sym link, because when I did it, splunk couldn't find my script.

The alert manager is actual running properly, but I can't manipulate the fields of the incident on the incident settings.
I can' because the search on the incident_settings page doesn't produce any results, so basically my file : inputlookup incident_settings doesn't exist.
Splunk is running as root, the permission of all my apps, searches, everything are global. I m also able to query my kv stores, I checked with all the other lookup files that the alert manager creates.
Checking on splunkd.log I got this error:

   11-27-2015 11:23:07.217 +0000 ERROR script - sid:scheduler__admin_aW50ZWdyaXR5LXNpZW0__RMD5ffc946a04a0b88fb_at_1448623380_16769 command="runshellscript", Script: /opt/splunk/bin/scripts/alert_handler.py exited with status code: 1

That's, I guess, is the reason why I'm not able to write on the incident_results lookup.
Could please someone helps me to solve this issue? I think is only related to the script.

Thanks a million.

0 Karma
1 Solution

Federica_92
Communicator

Ok, I found a solution.
The problem wasn't the script but the incident settings page, basically I copied the xml code from an older version of the alert manager in the new one and it's working fine : )

View solution in original post

0 Karma

Federica_92
Communicator

Ok, I found a solution.
The problem wasn't the script but the incident settings page, basically I copied the xml code from an older version of the alert manager in the new one and it's working fine : )

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...