Splunk IT Service Intelligence

Getting error creating a new notable event aggregation policy

Allenspach
Engager

No matter which rule I'm adding, I always receive the following error message:
Error in 'itsirulesengine' command: Invalid message received from external search command during setup, see search.log.

Labels (2)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee
0 Karma

Allenspach
Engager

HI @esnyder_splunk,

 

Permission was denied, thanks a lot it's working now