All Apps and Add-ons

Can't perform a GET action with this add-on

pwild_splunk
Splunk Employee
Splunk Employee

I'm trying to perform a simple GET action with this add-on but I'm not GETing anywhere.

This is being reported in the logs.

ERROR sendmodalert - Error in 'sendalert' command: Alert script returned error code 4.

Looking through the code this error reports if the CIM app is not installed. Installing the app makes no difference.

I'm setting these within the alert
Endpoint: http://host.domain.local:5000/command
Query string params: cmd=disarm&master_pin=ABCD
http method: GET

Any suggestions as to what I'm doing wrong?

Tags (1)
0 Karma
1 Solution

brendanmacooper
Explorer

@pwild_splunk Can you try setting the ingestion index. There was a bug where this option needed to be set even if it wasn't used.

I have a new version for Splunk 8 coming out soon™ that will fix this and a couple of other issues

View solution in original post

0 Karma

brendanmacooper
Explorer

@pwild_splunk Can you try setting the ingestion index. There was a bug where this option needed to be set even if it wasn't used.

I have a new version for Splunk 8 coming out soon™ that will fix this and a couple of other issues

0 Karma

pwild_splunk
Splunk Employee
Splunk Employee

Thanks Brendan, I already had the ingestion index set when I was getting that error. However... I put dummy data in every field and that solved the problem. The only field I didn't have data in was "Ingestion safety max size" which I arbitrarily set to 200 (I assume this is bytes???). This solved the problem.
Many thanks!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...