I create correlation search and set in ITSI App. But did not appear Notable Events Review to review notable events.
I get these errors:
05-04-2018 12:43:32.008 +0900 ERROR SearchScheduler - Error in 'sendalert' command: Alert script returned error code 255.,
05-04-2018 12:44:19.635 +0900 ERROR sendmodalert - action=itsi_event_generator STDERR - AuthenticationError: Autologin succeeded, but there was an auth error on next request. Something is very wrong.
ITSI Version : 3.1
Splunk Enterprise Verion :7.1