<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert Not Triggering in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453761#M8007</link>
    <description>&lt;P&gt;Do you really mean &lt;CODE&gt;returning 0 events&lt;/CODE&gt; or do you mean &lt;CODE&gt;not creating alerts&lt;/CODE&gt;?  If the latter, did you add the &lt;CODE&gt;Alert Action&lt;/CODE&gt; called Add to Triggered Alerts`?  Also, for email to gmail, go here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html"&gt;https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2019 13:09:36 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-07-08T13:09:36Z</dc:date>
    <item>
      <title>Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453747#M7993</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I'm very new to SPLUNK and was trying to generate the email alerts for the search.&lt;/P&gt;

&lt;P&gt;When i do the same search in the "Search &amp;amp; Reporting" it's giving me the results where as i configure an alert for the same but it's returning me 0 events.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Search:&lt;/STRONG&gt;&lt;BR /&gt;
source="C:\TestSplunklog.log" host="" index="boxtypereal" sourcetype="boxtype_real" "** ABL Debug-Alert Stack Trace **"&lt;/P&gt;

&lt;P&gt;Alert:&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7275i789A672FA7DE3640/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 04:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453747#M7993</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2019-07-02T04:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453748#M7994</link>
      <description>&lt;P&gt;@irangapw,&lt;/P&gt;

&lt;P&gt;are you using same "time range" in both search window and alert ? &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 12:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453748#M7994</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2019-07-02T12:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453749#M7995</link>
      <description>&lt;P&gt;Hi  irangapw,&lt;BR /&gt;
At first check the time range and remember that you can change it only in the alert window.&lt;BR /&gt;
Then check the quotes (some of them aren't mandatory!) and the source value.&lt;BR /&gt;
Then check if in the same selected time range there are results (for this test don't use dinamic values as erarliest and latest but a fixed value: e.g. earliest=-2h@h  latest=-h@h.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453749#M7995</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-02T13:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453750#M7996</link>
      <description>&lt;P&gt;Things to check:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;What is the timepicker in the saved search?
Who is the search `running as` (the owner of the search or the system)?
Maybe emails don't work; have you tested with `| makeresults | eval ... | sendemail`?
Maybe emails don't work; have you tested with the `Add to Triggered Alerts` action?
Maybe you would like an email every time the alert runs (whether or not it has any results) and you have your alert set to `Once for Each Result` instead of `Digest`.  In the former case, it will not fire for `number of results equals 0`, but i the latter case it will.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 02 Jul 2019 14:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453750#M7996</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-02T14:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453751#M7997</link>
      <description>&lt;P&gt;Hi, i have specified the time in the "Time Range Picker" and its the same time range.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 04:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453751#M7997</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2019-07-03T04:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453752#M7998</link>
      <description>&lt;P&gt;Hi Giuseppe, &lt;BR /&gt;
i will add the time range to the search in the alert and check.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 04:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453752#M7998</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2019-07-03T04:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453753#M7999</link>
      <description>&lt;P&gt;Ok,&lt;BR /&gt;
if you're satisfied of this answer, please accept and/or upvote it.&lt;BR /&gt;
bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 12:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453753#M7999</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-03T12:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453754#M8000</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
I updated the search string as follows.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;source="TestSplunklog2.log" sourcetype="TestLog2" "&lt;/STRONG&gt; ABL Debug-Alert Stack Trace &lt;STRONG&gt;" earliest=-3d@d latest=-h@h&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;It gives me the results as 23 events when i open it in the search. But i'm still not getting the email.&lt;BR /&gt;
Below is the alert configurations:&lt;BR /&gt;
&lt;STRONG&gt;Alert-01&lt;/STRONG&gt;&lt;BR /&gt;
Enabled: Yes. Disable&lt;BR /&gt;
App: search &lt;BR /&gt;
Permissions:Private. Owned by admin. Edit&lt;BR /&gt;
Modified:5 Jul 2019 09:32:15&lt;BR /&gt;
Alert Type:Scheduled. Hourly, at 45 minutes past the hour. Edit&lt;BR /&gt;
Trigger Condition:Number of Results is &amp;gt; 0. Edit&lt;BR /&gt;
Actions:1 Action Send email &lt;/P&gt;

&lt;P&gt;** I checked the "scheduler.log" and it has below entry for my alert.&lt;BR /&gt;
07-05-2019 09:45:07.195 +0530 INFO  SavedSplunker - savedsearch_id="admin;search;Alert-01", search_type="scheduled", user="admin", app="search", savedsearch_name="Alert-01", priority=default, status=success, digest_mode=1, scheduled_time=1562300100, window_time=0, dispatch_time=1562300100, run_time=0.298, result_count=23, alert_actions="email", sid="scheduler_&lt;EM&gt;admin&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD5a4aa4f0eb0032e9c_at_1562300100_11", suppressed=0, thread_id="AlertNotifierWorker-0", workload_pool=""&lt;/P&gt;

&lt;P&gt;But i did not get any email. &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453754#M8000</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2020-09-30T01:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453755#M8001</link>
      <description>&lt;P&gt;Hi irangapw,&lt;BR /&gt;
let me understan: this is the only alert that has problems or all the alerts doesn't send eMail?&lt;BR /&gt;
In first case, we continue to debug the alert, otherwise we try to understand if there are problems in eMail configuration.&lt;BR /&gt;
Anyway, in alert's actions set also "add to triggered alerts", in this way you can see if the problem is on alert or on eMail [Activity -- Triggered alerts].&lt;BR /&gt;
If alert is correctly triggered, you have, at first, to check the eMail configuration [Settings -- Server Settings -- eMail settings] and then search in _internal index if there are error messages.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 07:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453755#M8001</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-05T07:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453756#M8002</link>
      <description>&lt;P&gt;Check for errors like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_* (ERR* OR FAIL* OR WARN* OR CANNOT) (email OR sendemail)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 06 Jul 2019 00:06:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453756#M8002</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-06T00:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453757#M8003</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
As you mentioned i added the alert's action to "Add to triggered alerts" and now i can see the entries of my alert. Seems some issue with my email configurations.&lt;BR /&gt;
I didn't add any specific configurations there. If my email is gmail one, do i need to modify the configurations.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 05:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453757#M8003</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2019-07-08T05:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453758#M8004</link>
      <description>&lt;P&gt;Hi irangapw,&lt;BR /&gt;
ok, let me know if you've solved it.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 07:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453758#M8004</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-08T07:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453759#M8005</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I followed the steps given in below link to configure the email settings. But i still don't get the email. Will you be able to help me with it.&lt;BR /&gt;
&lt;A href="https://splunkonbigdata.com/2018/09/03/how-to-configure-email-alerting-using-gmail-smtp-in-splunk/"&gt;https://splunkonbigdata.com/2018/09/03/how-to-configure-email-alerting-using-gmail-smtp-in-splunk/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Find below my configurations:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;Mail Host -&lt;/STRONG&gt; smtp.gmail.com:587&lt;BR /&gt;
&lt;STRONG&gt;Email security -&lt;/STRONG&gt; TLS&lt;BR /&gt;
&lt;STRONG&gt;Username -&lt;/STRONG&gt; &lt;A href="mailto:email@gmail.com"&gt;email@gmail.com&lt;/A&gt;&lt;BR /&gt;
&lt;STRONG&gt;Password   -&lt;/STRONG&gt; email password&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 10:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453759#M8005</guid>
      <dc:creator>irangapw</dc:creator>
      <dc:date>2019-07-08T10:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453760#M8006</link>
      <description>&lt;P&gt;Hi irangapw,&lt;BR /&gt;
at first check if the used ports are correctly opened, try using &lt;CODE&gt;telnet smtp.gmail.com 587&lt;/CODE&gt;&lt;BR /&gt;
then are you sure that username is &lt;CODE&gt;email@gmail.com&lt;/CODE&gt; and not &lt;CODE&gt;email&lt;/CODE&gt; ?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 11:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453760#M8006</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-08T11:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Not Triggering</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453761#M8007</link>
      <description>&lt;P&gt;Do you really mean &lt;CODE&gt;returning 0 events&lt;/CODE&gt; or do you mean &lt;CODE&gt;not creating alerts&lt;/CODE&gt;?  If the latter, did you add the &lt;CODE&gt;Alert Action&lt;/CODE&gt; called Add to Triggered Alerts`?  Also, for email to gmail, go here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html"&gt;https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 13:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Not-Triggering/m-p/453761#M8007</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-08T13:09:36Z</dc:date>
    </item>
  </channel>
</rss>

