We have implemented Alert manager in our prod environment.
The problem we are facing is that when we try to assign the alerts to a user in Splunk it is not working whereas when we try to do the same thing from the other search head it's getting assigned properly.
I checked the replication bundle status, artifacts count but didn't find any clue as to why this is happening.
Can someone explain as to why this is happening.
Check for kvstore issues by searching
index=_internal sourcetype=mongod log_level=error
Correct any errors you see.
Also If you have a newer version of splunk there is a “Search Head Clustering” link in the settings drop down. It might have some clues too.
Not sure if you were able to fix this but are you using "Alert Manager" app from splunkbase? If yes, what is the version of the app?
Looks like the new version 2.2.2 has enhanced support for search head cluster.