I can't say why this is happening, but the 'category, subcategory, tags' are optional fields.
First I would make sure your user you are looking at the dash has alert manager permissions.
Second I like to use the "Add to Triggered Alerts" option from alert actions along with the "Alert Manager" option. This way you can verify your alert is working as expected with the splunk alerting subsystem outside of alert manager.
Once you have alerts showing in "Triggered Alerts" you should see them in the dashboard context.
you can also check the index you assigned at install for any incidents, and the kvstore too with
The user for alert manager is the admin account created at install, this was in there by default.
I've used the 'add to triggered alerts' option, and can see the output in Alert Manager > Alerts > Configured Alert. It loads a menu with 'trigger history' and in the actions column you can do 'view history'. So I can see there is some output recorded for those alerts setup.
Just can't work out why all the incident numbers are 0, even with the time range set to way back.
I've just installed alert manager and I seem to be having the same problem. The alerts are triggering and I can see the incidents in the KV store, but nothing on the dashboard. Did you find a solution?