Splunk ITSI

Getting error creating a new notable event aggregation policy

Allenspach
Engager

No matter which rule I'm adding, I always receive the following error message:
Error in 'itsirulesengine' command: Invalid message received from external search command during setup, see search.log.

Labels (2)
0 Karma

esnyder_splunk
Splunk Employee
Splunk Employee
0 Karma

Allenspach
Engager

HI @esnyder_splunk,

 

Permission was denied, thanks a lot it's working now

Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...