Splunk Dev

Why am I getting an error when creating Apps with App builder when testing Python?

jtlittle
Path Finder

this alert action gave me an error when testing the python.

2018-03-07 18:34:42,033 ERROR pid=24690 tid=MainThread file=cim_actions.py:message:271 | sendmodaction - signature="Error: 'module' object has no attribute 'process_event'. Please double check spelling and also verify that a compatible version of Splunk_SA_CIM is installed." action_name="test_alert" search_name="test_arf" sid="1520447680.116" rid="0" app="TA-fancydudeapp" user="admin" action_mode="adhoc" action_status="failure"
0 Karma

jtlittle
Path Finder

I found this in the error logs. I am trying to just create alert actions to add .json alerts to each event I alert on.

So its a python script which uses slack webhook to send the alert to with the crafted .json message.

The `os` module/method can be used to execute filesystem commands.

I would have an alert

1) alert action - slack alert with $ results.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...