Hmm, hard nail this one...
Did add to savesearches.conf
action.nimsoft.param.result_count = $job.resultCount$
action.nimsoft.param.search_query = $job.search$
Restarted Splunk, still same
...search_name=TestAlarm; configuration=; result=}
Checking internal log, only info messages
10-26-2017 14:49:29.685 +0200 INFO SavedSplunker - savedsearch_id="nobody;klp_nimsoft_custom_alerts;TestAlarm", search_type="scheduled", user="admin", app="klp_nimsoft_custom_alerts", savedsearch_name="TestAlarm", priority=default, status=success, digest_mode=0, scheduled_time=1509022140, window_time=0, dispatch_time=1509022141, run_time=0.875, result_count=23, alert_actions="logevent,nimsoft", sid="scheduler__admin_a2xwX25pbXNvZnRfY3VzdG9tX2FsZXJ0cw__TestAlarm_at_1509022140_14", suppressed=0, fired=23, skipped=0, action_time_ms=26641, thread_id="AlertNotifierWorker-0", message=""
and
index=_internal component=ScriptRunner
actually does return
10-26-2017 14:45:54.463 +0200 ERROR ScriptRunner - Couldn't start child process. script="C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -f D:\splunk\etc\apps\klp_nimsoft_custom_alerts\bin\testArguments.ps1 --execute"
But it seems to be a false positive, since the log file is being updated.
... View more