Splunk ITSI

Why Run a Script is not executed in ITSI after Splunk core version upgrade?

hasegawaarte
Explorer

Hi,

In ITSI > Notable Event Aggregation Policies > Action Rules, "Run a script" can no longer be executed.

The work that triggered the event to occur
- Splunk Core Version Up (8.2.7 > 9.0.5.1)

Environment before the work
- Splunk Core 8.2.7
- ITSI 4.11.6
- Configure Run a Script [File name] "patlite.sh RED" > Running enabled
Post-work environment
- Splunk Core 9.0.5.1
- ITSI 4.11.6
- Configure Run a Script [File name] "patlite.sh RED" > Not working

Script Deployment Location
/opt/splunk/etc/apps/SA-ITOA/bin/scripts/patlite.sh

The ITSI version has not been changed, only the Splunk Core version change, but is there some configuration change that needs to be made?

Labels (3)
Tags (1)
0 Karma

skramp
SplunkTrust
SplunkTrust

do you see something in _internal regarding the execution of the script? What about other scripts, if you create a new action rule with a different script, does this work or are all scripts failing?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...