<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cloud - Not receiving splunk alert emails in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607876#M14089</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;this sounds like there are one or more mail servers between SC and your mail servers which have some issues and cannot deliver mails online. They just queued those and send those later on when temporary resource issues have fixed. In old days that was quite common situation when servers and users has more limited quotas etc.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Tue, 02 Aug 2022 07:59:33 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-08-02T07:59:33Z</dc:date>
    <item>
      <title>Splunk Cloud - Why are we not receiving Splunk alert emails?</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607648#M14075</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We are unable to get the alert emails even when the events matching the alert condition is present in Splunk cloud.&lt;/P&gt;
&lt;P&gt;Please help how we can resolve this?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 14:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607648#M14075</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-08-02T14:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607654#M14077</link>
      <description>&lt;P&gt;Search splunkd.log for "sendemail" to see if Splunk is reporting errors sending email.&amp;nbsp; If not then your email provider may be discarding the messages as spam.&amp;nbsp; Contact them.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 13:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607654#M14077</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-31T13:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607658#M14078</link>
      <description>&lt;P&gt;Hi, we are also facing the same issue since this morning around 11 AM BST. No scheduled alert/report emails are not being sent. also tried the test email but it didn't work as well. thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 14:23:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607658#M14078</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-07-31T14:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607659#M14079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tried sending an email using this search but no luck.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main | head 5 | sendemail to="firstname.lastname@email.address" server="localhost" subject="Test Mail" message="This is an example message" sendresults=true inline=true format=raw sendpdf=true&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, when checking below search, it doesn't show any errors:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_internal" source="/opt/splunk/var/log/splunk/python.log" sendemail&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;INFO sendemail:184 - Sending email&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;INFO sendemail:1516 - Generated PDF for email&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;we have tried checking the emails for two different domains (where we have received emails until yesterday) and no issues with email blocking/black listing.&lt;/P&gt;&lt;P&gt;can you please suggest what else could be checked?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 14:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607659#M14079</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-07-31T14:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607674#M14080</link>
      <description>&lt;P&gt;Something changed yesterday to prevent Splunk Cloud emails from being delivered.&amp;nbsp; I suggest open a Support Request to have Splunk check things on their end and also working with your network team to verify Splunk Cloud email is allowed in.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 17:54:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607674#M14080</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-31T17:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607857#M14088</link>
      <description>&lt;P&gt;thanks,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;- We have raised a ticket with support for this - We also checked with internal it team and no emails were blocked - also the emails were not received by other domain as well.&amp;nbsp; these&amp;nbsp;emails were not received for almost 4 hours and then without any actions, it started.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 06:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607857#M14088</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-08-02T06:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607876#M14089</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;this sounds like there are one or more mail servers between SC and your mail servers which have some issues and cannot deliver mails online. They just queued those and send those later on when temporary resource issues have fixed. In old days that was quite common situation when servers and users has more limited quotas etc.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 07:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607876#M14089</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-08-02T07:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud - Not receiving splunk alert emails</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607957#M14094</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it was a case of queueing, we would have received all the hourly email alerts once the temp resource issues were fixed – but it was not the case – we completely missed the emails (and not received lately).&lt;/P&gt;&lt;P&gt;Also, there were different email servers affected and only Splunk emails were not being received – without making any changes on these email servers, we started receiving emails at around 15:00 BST – the issue was only observed between 11:00-15:00 BST on 31st Jul.&lt;/P&gt;&lt;P&gt;Do you suggest if anything more specific that I should check?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 18:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Cloud-Why-are-we-not-receiving-Splunk-alert-emails/m-p/607957#M14094</guid>
      <dc:creator>madhav_dholakia</dc:creator>
      <dc:date>2022-08-02T18:06:13Z</dc:date>
    </item>
  </channel>
</rss>

