In our environment Nagios and Splunk are integrated. We configured an alert in Nagios monitoring tool which fetches data from Splunk but in Nagios monitoring tool, it is showing as "UNKNOWN - Error in Application name "wms" ".
The alert is configured in such that it is using the script check_splunk_savedsearch_value.sh and it is taking three arguments.
check_splunk_savedsearch_value.sh -a wms -s "WMOS - EW - Number of Allocation records" -w 1
[root@nagios server]# ./check_splunk_savedsearch_value.sh -a wms -s "WMOS - EW - Number of Allocation records" -w 1
UNKNOWN - no output returned from splunk.ce.corp|"wms:WMOS - EW - Number of Allocation records"=ERROR
When we ran the script in debugging mode, the following command is not returning any output.