All Apps and Add-ons

Alert Manager Enterprise - Event Results are not showing in Data tab

Nithiya1
Loves-to-Learn

Hello,

I have encountered an issue with the Alert Manager Enterprise application. 

Alerts are getting triggered and can see the events in AME. But couldn't find event results in Data Tab.

 

Could see below error when click on events:

Failed to parse search results

Retrieving workflow actions failed. Please check your connection and your permissions.

 

Do you have any suggestion for how to get data here?

 

Thank you

 

Labels (2)
0 Karma

Nithiya1
Loves-to-Learn

I could see below error

error="12 validation errors for NotificationScheme flows.trigger_condition.MatchComposite.conditions.0.MatchComposite.composite_type Field required [type=missing, input_value={'component_type': 'leaf'...lue': 'ame.status_name'}, input_type=dict] For further information visit https://errors.pydantic.dev/2.5/v/missing

 

Any idea how to fix it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nithiya1 ,

what is the sharing level of your alerts?

to be visible in Alert Manager, they must be Global.

Ciao.

Giuseppe

0 Karma

Nithiya1
Loves-to-Learn

Hello @gcusello 

 

I have changed sharing level to Global.  But still i couldn't see results under data tab.

0 Karma

Nithiya1
Loves-to-Learn

Any update here please?

 

Thanks in Advance!!

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...