All Apps and Add-ons

Splunk Add-on for Amazon Web Services: Alert isn't published to SNS due to empty message content

splunk82
New Member

Hi,

I am using the Splunk Add-on and App for Amazon Web Services (AWS). I enabled one of the default alerts and added a AWS Simple Notification Service (SNS) alert for trigger actions. But i am not receiving SNS alerts.

When i check the logs, I see "SNSPublisherError: Alert isn't published to SNS due to empty message content"

Mandatory fields for SNS alerts are Account, Region, Topic Name, Message ($result.message$) and all of them are correct. Can someone point me in the right direction as to what i might be missing?

0 Karma

lim2
Communicator

your SPL output|eval message= host." ".sourcetype ." ". _raw|awssnsalert account="Account_to_connect_AWS" region="us-east-1" topic_name="topic_name" publish_all=1

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...