All Apps and Add-ons

Alert Manager Enterprise - Event Results are not showing in Data tab

Nithiya1
Loves-to-Learn

Hello,

I have encountered an issue with the Alert Manager Enterprise application. 

Alerts are getting triggered and can see the events in AME. But couldn't find event results in Data Tab.

 

Could see below error when click on events:

Failed to parse search results

Retrieving workflow actions failed. Please check your connection and your permissions.

 

Do you have any suggestion for how to get data here?

 

Thank you

 

Labels (2)
0 Karma

Nithiya1
Loves-to-Learn

I could see below error

error="12 validation errors for NotificationScheme flows.trigger_condition.MatchComposite.conditions.0.MatchComposite.composite_type Field required [type=missing, input_value={'component_type': 'leaf'...lue': 'ame.status_name'}, input_type=dict] For further information visit https://errors.pydantic.dev/2.5/v/missing

 

Any idea how to fix it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nithiya1 ,

what is the sharing level of your alerts?

to be visible in Alert Manager, they must be Global.

Ciao.

Giuseppe

0 Karma

Nithiya1
Loves-to-Learn

Hello @gcusello 

 

I have changed sharing level to Global.  But still i couldn't see results under data tab.

0 Karma

Nithiya1
Loves-to-Learn

Any update here please?

 

Thanks in Advance!!

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...