All Apps and Add-ons

Splunk Alert manager app is not working for user.

sridharlakshman
New Member

Hi Team,

We have installed the alert manager app on SH and it is working fine for admin but it is not working for user.

When user login and access the Alert Manager app and it is fetching the dashboard and view from another app.

Can anyone faced such a kind of issue.

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you already read the documentation at http://docs.alertmanager.info/en/latest/configuration_manual/ ?

Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.

Then you can find a procedure to add Virtual Users to the App.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi gcusello,

Thanks for your information. let me explain issue again.

when we login with admin account we are able to view Alert Manager app view and dashboard.

When we login with user account we are not able to view Alert Manager app view and dashboard. instead of Alert Manager view and dashboard we are able to view other app view and dashboard. Even we given read/write permission to the user.
alt text

https://ibb.co/z7RWxFd
https://ibb.co/p0DPk48

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
this means that you configured other users than admin as Alert Manager Virtual Users, is it correct?

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

sridharlakshman
New Member

Hi Giuseppe.

I am taking about splunk user. as user not able to view alert manager dashboard and view.

https://ibb.co/z7RWxFd

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sridharlakshmanan,
did you configured other users than admin as Alert Manager Virtual Users, following the below procedure?

Alert Manager Users
Users in the Alert Manager are supposed to be virtual. In addition to users in Splunk's ecosystem, e.g. Splunk internal users or users from an external LDAP repository, virtual Alert Managers users allow Incident assignment to external parties without creating them as a real Splunk user.
Note: There is no additional functionality than assigning Incidents to such users. They can't login to Splunk.
Add a Virtual Alert Manager user:
Open Settings -> User Settings in the > Alert Manager Ensure the active user directory is set to both Fill in a username and his e-mail address (can be used as current_owner variable in Notification Schemes) and press Save
Users Go back to the Incident Posture view and assign an Incident to the new user

I'm not speaking of normal Splunk Users, I'm speaking of setting the other users as Virtual users inside Alert manager following the procedure described in the documentation.

Ciao.
Giuseppe

0 Karma

Sucheta
New Member

Hi,

 

Am also facing similar issue, and couldnot understand the issue. The answer is not clear. Can anyone help?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...