All Apps and Add-ons

Splunk Alert manager app is not working for user.

sridharlakshman
New Member

Hi Team,

We have installed the alert manager app on SH and it is working fine for admin but it is not working for user.

When user login and access the Alert Manager app and it is fetching the dashboard and view from another app.

Can anyone faced such a kind of issue.

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you already read the documentation at http://docs.alertmanager.info/en/latest/configuration_manual/ ?

Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.

Then you can find a procedure to add Virtual Users to the App.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi gcusello,

Thanks for your information. let me explain issue again.

when we login with admin account we are able to view Alert Manager app view and dashboard.

When we login with user account we are not able to view Alert Manager app view and dashboard. instead of Alert Manager view and dashboard we are able to view other app view and dashboard. Even we given read/write permission to the user.
alt text

https://ibb.co/z7RWxFd
https://ibb.co/p0DPk48

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
this means that you configured other users than admin as Alert Manager Virtual Users, is it correct?

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi Giuseppe.

I am taking about splunk user. as user not able to view alert manager dashboard and view.

https://ibb.co/z7RWxFd

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you configured other users than admin as Alert Manager Virtual Users, following the below procedure?

Alert Manager Users
Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.
Note: There is no additional functionality than assigning Incidents to such users. They can't login to Splunk.
Add a Virtual Alert Manager user:
Open Settings -> User Settings in the > Alert Manager Ensure the active user directory is set to both Fill in a username and his e-mail address (can be used as current_owner variable in Notification Schemes) and press Save
Users Go back to the Incident Posture view and assign an Incident to the new user

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

Sucheta
New Member

Hi,

 

Am also facing similar issue, and couldnot understand the issue. The answer is not clear. Can anyone help?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...