A saved search that ends with
| sendalert risk param._risk_score=risk_score
runs fine, but fails when run as a saved search with the error
Error in 'sendalert' command: Alert script returned error code 3.
and in search.log just before it shows
sendmodalert - action=risk STDERR - ERROR: [Errno 2] No such file or directory: u'/opt/splunk/var/run/splunk/dispatch/scheduler__admin__XX/results.srs.gz'
Anyone run risk actions from saved searches successfully?
This usually happens when there are 0 results from the preceding search. If the results are more than 0 then you'll not see this error. So its safe to ignore this.