Im executing my custom alert action with sendalert action_name command and it executes correctly.
I can see the output in job logs but it doesnt get indexed in _internal index as standard alerts does.
Can I make somehting to make it work?
Have a look at answer https://answers.splunk.com/answers/737102/custom-alerts-logs-dont-appear-in-internal-index.html
Yes, my observation is the same. Although I hope for some solution still.