Splunk Enterprise Security

Using "sendalert risk" from saved search fails?

bowesmana
SplunkTrust
SplunkTrust

A saved search that ends with

| sendalert risk param._risk_score=risk_score

runs fine, but fails when run as a saved search with the error

Error in 'sendalert' command: Alert script returned error code 3.

and in search.log just before it shows

sendmodalert - action=risk STDERR -  ERROR: [Errno 2] No such file or directory: u'/opt/splunk/var/run/splunk/dispatch/scheduler__admin__XX/results.srs.gz'

Anyone run risk actions from saved searches successfully?

Labels (1)

neelshah
Path Finder

This usually happens when there are 0 results from the preceding search. If the results are more than 0 then you'll not see this error.  

So its safe to ignore this.

0 Karma
Get Updates on the Splunk Community!

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...