Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Alert Manager: How to resolve multiple errors received such as "Error in 'sendalert' command: Alert script returned error code 1"?

$
0
0
Hi I am trying to use Alert Manager in Splunk. Once the alert is triggered and alert manager will do something, it always gets below error. Then there is nothing generated for alert manager data. Does anyone have any idea ? "11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - Traceback (most recent call last): 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - File "/opt/splunk/etc/apps/alert_manager/bin/alert_manager.py", line 427, in 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - createIncidentChangeEvent(event, metadata['job_id'], settings.get('index')) 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - File "/opt/splunk/etc/apps/alert_manager/bin/alert_manager.py", line 157, in createIncidentChangeEvent 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - input.submit(event, hostname = socket.gethostname(), sourcetype = 'incident_change', source = 'alert_handler.py', index=index) 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - File "/opt/splunk/lib/python2.7/site-packages/splunk/input.py", line 180, in submit 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - raise splunk.RESTException, (serverResponse.status, msg_text) 11-04-2016 20:51:01.519 +0000 ERROR sendmodalert - action=alert_manager STDERR - splunk.RESTException: [HTTP 400] ["message type=WARN code=None text=supplied index 'alerts' missing;"] 11-04-2016 20:51:01.531 +0000 INFO sendmodalert - action=alert_manager - Alert action script completed in duration=312 ms with exit code=1 11-04-2016 20:51:01.532 +0000 WARN sendmodalert - action=alert_manager - Alert action script returned error code=1 11-04-2016 20:51:01.532 +0000 ERROR sendmodalert - Error in 'sendalert' command: Alert script returned error code 1. 11-04-2016 20:51:01.532 +0000 ERROR SearchScheduler - Error in 'sendalert' command: Alert script returned error code 1., search='sendalert alert_manager results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__admin__launcher__test_at_1478292660_48/results.csv.gz" results_link="http://tbsplunkpeer4.qa1.iad2.xaxis.net:8000/app/launcher/@go?sid=scheduler__admin__launcher__test_at_1478292660_48"' "

Viewing all articles
Browse latest Browse all 47296

Trending Articles