AIQUM Fails to Forward Alerts to Splunk Due to Maintenance Account Lockout
Applies to
- Active IQ Unified Manager (AIQUM) 9.X+
- AIQUM configured to run external scripts
- All OS platforms
Issue
- AIQUM intermittently fails to forward alerts to a Splunk server, resulting in missed critical notifications.
- AIQUM captures events but does not forward them as expected.
- Rebooting the AIQUM instance temporarily resolves the issue, but it recurs after several days of operation.
- Alerts are not received by Splunk even though AIQUM shows the event as active.
- Maintenance account becomes locked.
Possible messages seen in logs:
WARN [ScriptExecutor-7] c.n.u.s.s.AuthenticationUtils(AuthenticationUtils.java:65) - Exception while sending a login request. 500 Internal Server Error: "ActiveIQ Unified Manager|Error Error 500 - Internal Server Error Please go back to the homepage and try again.". UM commands in the script file might fail to execute.INFO [ScriptExecutor-4] c.n.u.s.s.AlertScriptService(AlertScriptService.java:79) - Executing the script file with a null session idINFO [ScriptExecutor-4] c.n.u.s.s.AlertScriptService(AlertScriptService.java:108) - Script execution of file: netapp_splunk_forwarder.sh for EventID:208559 in progress..RbacUserManager: Account locked due to too many failed authentication attempts
