Installed Alert Manager on stand-alone Splunk server for testing without any problems. Great app. Replicated the installation process to a single SH and clustered indexers. Created the alerts index on SH and Indexers. Cannot seem to make it work. The only error found is the following (repeating every second). Any help in getting this running would be appreciated.
MongoModificationsTracker - Could not load configuration for collection 'drilldown_settings' in application 'alert_manager'. Collection will be ignored.
Never did resolve the "error message", only resolved the fact that the app would not work. Seems the two were/are not related and it works properly even with the error 😕
Never fails. Post a question, and murphy resolves the problem
May I please know what was the resolution as I am facing similar issue .
The resolution was to add a stanza to collections.conf, "[drilldown_settings]"