All Apps and Add-ons

Alert Manager Enterprise - Event Results are not showing in Data tab

Nithiya1
Explorer

Hello,

I have encountered an issue with the Alert Manager Enterprise application. 

Alerts are getting triggered and can see the events in AME. But couldn't find event results in Data Tab.

 

Could see below error when click on events:

Failed to parse search results

Retrieving workflow actions failed. Please check your connection and your permissions.

 

Do you have any suggestion for how to get data here?

 

Thank you

 

Labels (2)
0 Karma

Nithiya1
Explorer

I could see below error

error="12 validation errors for NotificationScheme flows.trigger_condition.MatchComposite.conditions.0.MatchComposite.composite_type Field required [type=missing, input_value={'component_type': 'leaf'...lue': 'ame.status_name'}, input_type=dict] For further information visit https://errors.pydantic.dev/2.5/v/missing

 

Any idea how to fix it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nithiya1 ,

what is the sharing level of your alerts?

to be visible in Alert Manager, they must be Global.

Ciao.

Giuseppe

0 Karma

Nithiya1
Explorer

Hello @gcusello 

 

I have changed sharing level to Global.  But still i couldn't see results under data tab.

0 Karma

Nithiya1
Explorer

Any update here please?

 

Thanks in Advance!!

 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...