Splunk ITSI

ITSI sendmodalert - Alert action script returned error code=255

jacob_smith14
Explorer

I am running itsi 4.9.2 and Splunk 8.1.2.  ITSI is not generating notable events because of this error.  My correlation searches find notable events but they do not get put anywhere because of this error.

I am on a disconnected network so I can't type it all:

WARN sendmodalert - action=itsi_event_generator - Alert action script returned error code 255.

INFO sendmodalert - action=itsi_event_generator - Alert action script completed in duration=1134ms with exit code 255.

There are a bunch of python errors ,most interesting:

ERROR sendmodalert - action=itsi_event_generator - STDERR - SA_ITOA_app_common.solnlib.packages.requests.exceptions.SSLError: HTTPSConnectionPool(127.0.0.1,port=8088): MAx retries exceeded with url: /services/collector (Caused by SSLError(SSLError(1, '[SSL:UNKNOWN_PROTOCOL] unknow protocol (_ssl.c:1106)')))

Not sure when this first started but any help is appreciated!

 

Thanks!

 

 

 

Labels (2)
0 Karma
1 Solution

jacob_smith14
Explorer

Forgot to update this one.....the fix is to make sure your HEC, or whatever is set on port 8088 is set to enableSSL=true.

./splunk cmd btool inputs list --debug | grep 8088

Wherever that file is, update that stanza to enableSSL=true.

View solution in original post

0 Karma

jacob_smith14
Explorer

Forgot to update this one.....the fix is to make sure your HEC, or whatever is set on port 8088 is set to enableSSL=true.

./splunk cmd btool inputs list --debug | grep 8088

Wherever that file is, update that stanza to enableSSL=true.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...