I’m currently running Splunk on my Windows XP SP3 and I'm trying to get a couple scripts to run after an alert triggers, but failing all the while. Not sure what I could be doing wrong.
The environment variable for SPLUNK_HOME = C:\Program Files\Splunk
Neither of these currently get triggered at all.
One thing that I have wondered is whether Splunk may be having an issue with the space between “Program” and “Files” in the SPLUNK_HOME environment variable.
Also, in my Perl script, I correctly reference the library (as shown below), per the online Splunk docs regarding this topic.
Any help or insight would be greatly appreciated.
asked 31 Aug '10, 18:29
This can be a complex problem and it's important to be thorough in checking that every step of the process (from scheduled search to alert script) is working as expected :
A) Is my scheduled search running?
B) Is my scheduled search generating the expected results?
C) Is my alert action being triggered?
D) Is my alert script working?