<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I created an Alert, is there any way to test it? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307583#M10718</link>
    <description>&lt;P&gt;try this &lt;/P&gt;

&lt;P&gt;index=xxxx sourcetype=xxxx earliest= latest= rest of the query along with condition |  sendemail to=\"&lt;A href="mailto:abc@123.com"&gt;abc@123.com&lt;/A&gt;\" format=\"html\" server=localhost subject=\"Alert for Data\" message=\"This is an alert for some data\" sendpdf=true"&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchReference/Sendemail"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchReference/Sendemail&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2017 18:41:54 GMT</pubDate>
    <dc:creator>sbbadri</dc:creator>
    <dc:date>2017-07-14T18:41:54Z</dc:date>
    <item>
      <title>I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307582#M10717</link>
      <description>&lt;P&gt;I created an alert for a condition that I want an email notification for going forward.  Setting up the alert is fairly straight forward.  I only want it to check at 15 minutes past the hour, for the past hour.  Now that I have it created, I would like to test it, but the condition I am looking for is from earlier in the day.  Is there a way to test that?  I want to make sure the email addresses I entered are correct and that those groups will receive the email if the condition is encountered again in the future.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 18:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307582#M10717</guid>
      <dc:creator>rwolinski</dc:creator>
      <dc:date>2017-07-14T18:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307583#M10718</link>
      <description>&lt;P&gt;try this &lt;/P&gt;

&lt;P&gt;index=xxxx sourcetype=xxxx earliest= latest= rest of the query along with condition |  sendemail to=\"&lt;A href="mailto:abc@123.com"&gt;abc@123.com&lt;/A&gt;\" format=\"html\" server=localhost subject=\"Alert for Data\" message=\"This is an alert for some data\" sendpdf=true"&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchReference/Sendemail"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchReference/Sendemail&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 18:41:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307583#M10718</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-07-14T18:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307584#M10719</link>
      <description>&lt;P&gt;couple of things here:&lt;BR /&gt;
if you know the condition existed earlier that day, just create a fake alert with same condition that searches that time range&lt;BR /&gt;
testing the emails is straight forward, use the sendmail command as described here and verify everybody receives email.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Sendemail#Examples"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Sendemail#Examples&lt;/A&gt;&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 18:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307584#M10719</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-14T18:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307585#M10720</link>
      <description>&lt;P&gt;This worked perfectly.  I everyone got the emails and exactly what we were expecting in them.  Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 19:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307585#M10720</guid>
      <dc:creator>rwolinski</dc:creator>
      <dc:date>2017-07-14T19:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307586#M10721</link>
      <description>&lt;P&gt;You could also test it directly from the search bar using the &lt;CODE&gt;sendalert&lt;/CODE&gt; command.  Docs &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchReference/Sendalert"&gt;here&lt;/A&gt; and &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/AdvancedDev/ModAlertsLog"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 21:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307586#M10721</guid>
      <dc:creator>wpreston</dc:creator>
      <dc:date>2017-07-14T21:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: I created an Alert, is there any way to test it?</title>
      <link>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307587#M10722</link>
      <description>&lt;P&gt;When I need to do this, I add a macro to the end of the search that will add fake data with an &lt;CODE&gt;append [|makeresults ...&lt;/CODE&gt; for test and &lt;CODE&gt;| noop&lt;/CODE&gt; for non-test.  When testing, just change the macro.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2017 03:41:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-created-an-Alert-is-there-any-way-to-test-it/m-p/307587#M10722</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-15T03:41:04Z</dc:date>
    </item>
  </channel>
</rss>

