Splunk ITSI

Why Run a Script is not executed in ITSI after Splunk core version upgrade?

hasegawaarte
Explorer

Hi,

In ITSI > Notable Event Aggregation Policies > Action Rules, "Run a script" can no longer be executed.

The work that triggered the event to occur
- Splunk Core Version Up (8.2.7 > 9.0.5.1)

Environment before the work
- Splunk Core 8.2.7
- ITSI 4.11.6
- Configure Run a Script [File name] "patlite.sh RED" > Running enabled
Post-work environment
- Splunk Core 9.0.5.1
- ITSI 4.11.6
- Configure Run a Script [File name] "patlite.sh RED" > Not working

Script Deployment Location
/opt/splunk/etc/apps/SA-ITOA/bin/scripts/patlite.sh

The ITSI version has not been changed, only the Splunk Core version change, but is there some configuration change that needs to be made?

Labels (3)
Tags (1)
0 Karma

skramp
SplunkTrust
SplunkTrust

do you see something in _internal regarding the execution of the script? What about other scripts, if you create a new action rule with a different script, does this work or are all scripts failing?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...