On our development servers, we upgraded a Splunk 6.1.3 search head to 6.3.2. After upgrading, we left Alert Manager alone, but are having issues adding users to the User Settings. I get a pop-up that says "There is at least one row with missing data. Check user and email (when notify_user is activated)."
There are users without email addresses. Is there a way to force off notify_user?
I then decided to upgrade and all seemed to go well, however, on the Incident Posture screen when you go to edit an incident, no users were showing up. I tested deleting all alert_manager users and that allowed the field to work. Do you have any suggestions?
↧