All Apps and Add-ons

Splunk Alert manager app is not working for user.

sridharlakshman
New Member

Hi Team,

We have installed the alert manager app on SH and it is working fine for admin but it is not working for user.

When user login and access the Alert Manager app and it is fetching the dashboard and view from another app.

Can anyone faced such a kind of issue.

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you already read the documentation at http://docs.alertmanager.info/en/latest/configuration_manual/ ?

Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.

Then you can find a procedure to add Virtual Users to the App.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi gcusello,

Thanks for your information. let me explain issue again.

when we login with admin account we are able to view Alert Manager app view and dashboard.

When we login with user account we are not able to view Alert Manager app view and dashboard. instead of Alert Manager view and dashboard we are able to view other app view and dashboard. Even we given read/write permission to the user.
alt text

https://ibb.co/z7RWxFd
https://ibb.co/p0DPk48

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
this means that you configured other users than admin as Alert Manager Virtual Users, is it correct?

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi Giuseppe.

I am taking about splunk user. as user not able to view alert manager dashboard and view.

https://ibb.co/z7RWxFd

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you configured other users than admin as Alert Manager Virtual Users, following the below procedure?

Alert Manager Users
Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.
Note: There is no additional functionality than assigning Incidents to such users. They can't login to Splunk.
Add a Virtual Alert Manager user:
Open Settings -> User Settings in the > Alert Manager Ensure the active user directory is set to both Fill in a username and his e-mail address (can be used as current_owner variable in Notification Schemes) and press Save
Users Go back to the Incident Posture view and assign an Incident to the new user

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

Sucheta
New Member

Hi,

 

Am also facing similar issue, and couldnot understand the issue. The answer is not clear. Can anyone help?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...