All Apps and Add-ons

Alert Manager Enterprise - Event Results are not showing in Data tab

Nithiya1
Loves-to-Learn

Hello,

I have encountered an issue with the Alert Manager Enterprise application. 

Alerts are getting triggered and can see the events in AME. But couldn't find event results in Data Tab.

 

Could see below error when click on events:

Failed to parse search results

Retrieving workflow actions failed. Please check your connection and your permissions.

 

Do you have any suggestion for how to get data here?

 

Thank you

 

Labels (2)
0 Karma

Nithiya1
Loves-to-Learn

I could see below error

error="12 validation errors for NotificationScheme flows.trigger_condition.MatchComposite.conditions.0.MatchComposite.composite_type Field required [type=missing, input_value={'component_type': 'leaf'...lue': 'ame.status_name'}, input_type=dict] For further information visit https://errors.pydantic.dev/2.5/v/missing

 

Any idea how to fix it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nithiya1 ,

what is the sharing level of your alerts?

to be visible in Alert Manager, they must be Global.

Ciao.

Giuseppe

0 Karma

Nithiya1
Loves-to-Learn

Hello @gcusello 

 

I have changed sharing level to Global.  But still i couldn't see results under data tab.

0 Karma

Nithiya1
Loves-to-Learn

Any update here please?

 

Thanks in Advance!!

 

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...