Community:AlertingScriptArgChanges405
From Splunk Wiki
Beginning with 4.0.5 there were changes in how arguments are passed to custom alerting scripts. The name of the saved search is no longer enclosed in double quotes.
4.0.4 $ARGV[0]= [1] $ARGV[1]= [sourcetype="backup_file"] $ARGV[2]= [sourcetype="backup_file"] $ARGV[3]= [test] $ARGV[4]= ["Saved Search [test] always(1)"] $ARGV[5]= [http://beefysup01:20000/app/search/@go?sid=scheduler_admin_search_test_at_1258155240_2004013643] $ARGV[6]= [] $ARGV[7]= [/opt/splunk4.0.4/var/run/splunk/dispatch/scheduler_admin_search_test_at_1258155240_2004013643/results.csv.gz] $ARGV[8]= [] 4.0.6 $ARGV[0]= [1] $ARGV[1]= [sourcetype="backup_file"] $ARGV[2]= [sourcetype="backup_file"] $ARGV[3]= [test] $ARGV[4]= [Saved Search [test] always(1)] $ARGV[5]= [http://beefysup01:20000/app/search/@go?sid=scheduler_admin_search_test_at_1258154100_991299485] $ARGV[6]= [] $ARGV[7]= [/opt/splunk4.0.6/var/run/splunk/dispatch/scheduler_admin_search_test_at_1258154100_991299485/results.csv.gz] $ARGV[8]= []