<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why my mail alerts are not running? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313988#M10766</link>
    <description>&lt;P&gt;Actually my mail alert sends to 100 individuals so i kept the mode as Once Per Result&lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2017 04:02:36 GMT</pubDate>
    <dc:creator>ASISH_9</dc:creator>
    <dc:date>2017-05-31T04:02:36Z</dc:date>
    <item>
      <title>Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313986#M10764</link>
      <description>&lt;P&gt;I have created a alert that sends 100 results to 100 indivisuals. The alert mode was kept as "Once per result".But each time it is triggered,it runs for 4 minutes and within that time only 4 people get the alert and rest don't.&lt;BR /&gt;
Please suggest to fix this problem&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2017 04:06:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313986#M10764</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-05-30T04:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313987#M10765</link>
      <description>&lt;P&gt;It is entirely likely that the problem is that you are being throttled by your email system itself.  The best way to handle this is to create an email distribution list in your email system so that you send to 1 email address and the email system distributes to everyone else.  Many enterprise companies use &lt;CODE&gt;xMatters&lt;/CODE&gt; and Splunk integrates with this well:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2901/"&gt;https://splunkbase.splunk.com/app/2901/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, &lt;CODE&gt;Once per result&lt;/CODE&gt; will send 100 emails to 100 people with 1 event in each email which is surely not what you desire; change to the other setting to send 1 email to 100 people with 100 events in each email.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2017 17:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313987#M10765</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-30T17:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313988#M10766</link>
      <description>&lt;P&gt;Actually my mail alert sends to 100 individuals so i kept the mode as Once Per Result&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 04:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313988#M10766</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-05-31T04:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313989#M10767</link>
      <description>&lt;P&gt;And in my output i am bringing a column email id.Based on this i am sending one mail to different individuals with their respective result.So i cant use here "Once Per  Search " mode&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 04:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313989#M10767</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-05-31T04:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313990#M10768</link>
      <description>&lt;P&gt;I am providing here an illustration of my search that would run as an alert:&lt;/P&gt;

&lt;P&gt;EnterpriseID        ReportingMonth      BookedHours    WorkingHours    Email                                  SupervisorID&lt;BR /&gt;
a.b.c                   May,2017                 12                           20                        &lt;A href="mailto:a.b.c@gmail.com"&gt;a.b.c@gmail.com&lt;/A&gt;             &lt;A href="mailto:a.x@gmail.com"&gt;a.x@gmail.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;
d.e.f                   May,2017                 20                           20                        &lt;A href="mailto:d.e.f@gmail.com"&gt;d.e.f@gmail.com&lt;/A&gt;             &lt;A href="mailto:a.1@gmail.com"&gt;a.1@gmail.com&lt;/A&gt; &lt;BR /&gt;
d.e.g                   May,2017                 19                           20                        &lt;A href="mailto:d.e.g@gmail.com"&gt;d.e.g@gmail.com&lt;/A&gt;             &lt;A href="mailto:a.2@gmail.com"&gt;a.2@gmail.com&lt;/A&gt;          &lt;/P&gt;

&lt;P&gt;The query is written in such a way that this quuery will send the booked hours and working hours result only to those who have booked hours less than working hours.&lt;BR /&gt;
Since individuals need to get the result here,so i have kept the alert mode as "Once per Result".I cannot use Once per search here.&lt;BR /&gt;
The problem is the alert only runs for 5 minutes and only send 4-5 results within those 5 minutes and then it expires.&lt;BR /&gt;
But i need all those who satisfy the mentioned condition to receive the mail alert.&lt;BR /&gt;
Please do the needful           &lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 09:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313990#M10768</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-05-31T09:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313991#M10769</link>
      <description>&lt;P&gt;How are you getting it to send to each user and not to all users?  Are you using tokens?  Show the entire search and the alert settings and maybe we can help (or devise an alternative).&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 15:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313991#M10769</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-20T15:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313992#M10770</link>
      <description>&lt;P&gt;Like i said,&lt;BR /&gt;
If email is &lt;A href="mailto:a.b.c@gmail.com"&gt;a.b.c@gmail.com&lt;/A&gt; the booked hours is 12 and working hours is 20.&lt;BR /&gt;
Since booked hours is less so an email should be sent from server to his mail notifying this.&lt;BR /&gt;
I cannot send it to all users at a time (which is "Once per search" mode in mail settings)  since every user must get his/her individual alerts. &lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 07:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313992#M10770</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-06-22T07:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why my mail alerts are not running?</title>
      <link>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313993#M10771</link>
      <description>&lt;P&gt;I am providing below a summary of my query:&lt;/P&gt;

&lt;P&gt;"|Query for calculating the number of days in a week|append[|Macro for bringing out latest values from TicketMaster source]&lt;BR /&gt;
|joining a primary key with another macro for calculating booked hours of respective employee|eval Email=employee+"@domain.com"|&lt;BR /&gt;
A Search command to extract those employees from the table whose booked hours is less than working hour&lt;/P&gt;

&lt;P&gt;note:working hours is calculated from the first statement of the query "Query for calculating the number of days in a week"." &lt;/P&gt;

&lt;P&gt;This query gives a table which contains Employee Id,booked hours ,working hours respective domain and email id along with their supervisor's Id.This sends an alert  to those employees who are mentioned in the table (which is generated by above query).&lt;/P&gt;

&lt;P&gt;Here are my mail settings:&lt;BR /&gt;
Expiration:after 24 hours&lt;BR /&gt;
Severity:Critical&lt;BR /&gt;
Schedule type : Cron&lt;BR /&gt;
Cron Schedule:runs the alert  every day except weekends "10 12 * * 1-5"&lt;BR /&gt;
alert mode:Once Per Result&lt;BR /&gt;
alert conditions:Always&lt;BR /&gt;
Throttling checkbox:not checked&lt;BR /&gt;
Alert Actions checkbox:checked&lt;BR /&gt;
To field: $result.Email$&lt;BR /&gt;
cc:$result.SupervisorId$&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 06:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-my-mail-alerts-are-not-running/m-p/313993#M10771</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-06-28T06:28:20Z</dc:date>
    </item>
  </channel>
</rss>

