All Apps and Add-ons

Alert manager - email notification

abasens
Engager

Hi,

I've recently installed the Alert Manager (and the add-on) on a search head cluster. I've added the Alert Manager trigger action to some saved searches and followed the instructions on how to configure email notification in Alert Manager. Using Splunk's email trigger action works for the same alert, but not when I try email notification using the Alert Manager. I see evidence in the alert_manager_notifications.log that it is trying to send a mail on the "incident_created" event:

/opt/splunk/var/log/splunk/alert_manager_notifications.log:

2019-03-07 14:05:07,174 INFO pid="141090" logger="alert_manager_notifications" message="Start trying to send notification to [u'[email protected]'] with event=incident_created of alert test alert manager" (NotificationHandler.py:189)

Would be great if somebody out there have any ideas on how to troubleshoot this.

Update:

I see this error in the alert_manager_notifications.log:

2019-03-11 20:45:46,449 ERROR pid="80153" logger="alert_manager_notifications" message="Unable to send notification. Continuing without sending notification. Unexpected Error: Traceback (most recent call last):
File "/opt/splunk/etc/apps/alert_manager/bin/lib/NotificationHandler.py", line 200, in send_notification
content = template.render(context)
File "/opt/splunk/etc/apps/alert_manager/bin/lib/jinja2/environment.py", line 989, in render
return self.environment.handle_exception(exc_info, True)
File "/opt/splunk/etc/apps/alert_manager/bin/lib/jinja2/environment.py", line 754, in handle_exception
reraise(exc_type, exc_value, tb)
File "/opt/splunk/etc/apps/alert_manager/default/templates/default.html", line 52, in top-level template code
{% for k in results[0] %}
UndefinedError: 'results' is undefined
" (NotificationHandler.py:332)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...