<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Alerts not sending e-mail in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486501#M8602</link>
    <description>&lt;P&gt;Hi @golcondar,&lt;BR /&gt;
I think that you already configured Splunk to send eMails and that there are other alerts that correctly run.&lt;/P&gt;

&lt;P&gt;At first, check if the dimension of the pdf exceed the limit of your eMail attachement.&lt;BR /&gt;
Then you can see in _internal, if there's some event related.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 13:46:43 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-03-06T13:46:43Z</dc:date>
    <item>
      <title>Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486500#M8601</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've created a Splunk alert (see below photos) and have found that it's not properly sending e-mails to my account upon being triggered.&lt;BR /&gt;
I opened the query in the search bar (from the alerts page) to verify that the message i'm looking for is actually showing up, which it is.&lt;/P&gt;

&lt;P&gt;I'm not sure what the problem might be.&lt;BR /&gt;
Please let me know if there's any other information which I could include that might be helpful.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8490i031ED19775531D39/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8491iBFE40D66F0CEA753/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 02:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486500#M8601</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-06T02:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486501#M8602</link>
      <description>&lt;P&gt;Hi @golcondar,&lt;BR /&gt;
I think that you already configured Splunk to send eMails and that there are other alerts that correctly run.&lt;/P&gt;

&lt;P&gt;At first, check if the dimension of the pdf exceed the limit of your eMail attachement.&lt;BR /&gt;
Then you can see in _internal, if there's some event related.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 13:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486501#M8602</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-03-06T13:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486502#M8603</link>
      <description>&lt;P&gt;First, try sending ad-hoc by using the &lt;CODE&gt;| sendemail&lt;/CODE&gt; command in your &lt;CODE&gt;SPL&lt;/CODE&gt;.  Then check here:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_* AND (SMTP OR sendemail OR email) AND (FAIL* OR ERR* OR TIMEOUT OR CANNOT OR REFUSED OR REJECTED)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Mar 2020 16:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486502#M8603</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-06T16:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486503#M8604</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I was able to get e-mail results by using |sendemail.&lt;BR /&gt;
However, my alert still did not trigger, and I also put in the query you placed above and got no results.&lt;BR /&gt;
I'll attach some images to the next post (it's not letting me attach them to this one) to show what i did.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 22:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486503#M8604</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-06T22:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486504#M8605</link>
      <description>&lt;P&gt;Looks like I can't add any more images to this post &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;
I took the query from my alert and added the |sendemail command to the end, so I know that the query itself is correct. &lt;/P&gt;

&lt;P&gt;I entered the below to search for errors:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;index=_* AND (SMTP OR sendemail OR email) AND (FAIL* OR ERR* OR TIMEOUT OR CANNOT OR REFUSED OR REJECTED)&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;but got no results.&lt;BR /&gt;
Any ideas on what I could do next?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 22:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486504#M8605</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-06T22:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486505#M8606</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I don't need the PDF attachment so I went ahead and deselected it. That didn't end up fixing the issue. I also wasn't able to get any results from searching _internal unfortunately.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 22:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486505#M8606</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-06T22:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486506#M8607</link>
      <description>&lt;P&gt;I have seen this happen before where people are expecting for an email to ALWAYS be sent when something fails but they have the &lt;CODE&gt;alert&lt;/CODE&gt; set with:&lt;BR /&gt;
&lt;CODE&gt;Trigger alert when&lt;/CODE&gt; = &lt;CODE&gt;Number of Results&lt;/CODE&gt; with &lt;CODE&gt;is equal to&lt;/CODE&gt; and &lt;CODE&gt;0&lt;/CODE&gt; combined with&lt;BR /&gt;
&lt;CODE&gt;Trigger&lt;/CODE&gt; = &lt;CODE&gt;For each result&lt;/CODE&gt;&lt;BR /&gt;
The solution is to set &lt;CODE&gt;Trigger&lt;/CODE&gt; = &lt;CODE&gt;Once&lt;/CODE&gt;.  If you stop and think about it, it makes TOTAL sense why it doesn't send the email.&lt;/P&gt;

&lt;P&gt;In your case, because you have an older version of Splunk, the GUI is a bit different; you need to click on &lt;CODE&gt;Per-Result&lt;/CODE&gt; and choose the other option, which I believe is &lt;CODE&gt;Digest&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 23:01:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486506#M8607</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-06T23:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486507#M8608</link>
      <description>&lt;P&gt;I'll try swapping it to "Per Result" instead of what I currently have and seeing if that works; i recall attempting that before and still not getting the e-mails.&lt;BR /&gt;
If it still doesn't work, i'll attempt it with Trigger=Once.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 00:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486507#M8608</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-07T00:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Alerts not sending e-mail</title>
      <link>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486508#M8609</link>
      <description>&lt;P&gt;Looks like it was an issue with permissions. I had a coworker who had created alerts before successfully follow the same process as me and the alert properly sent the e-mail.&lt;/P&gt;

&lt;P&gt;Thanks for the help everyone!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 22:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Splunk-Alerts-not-sending-e-mail/m-p/486508#M8609</guid>
      <dc:creator>golcondar</dc:creator>
      <dc:date>2020-03-09T22:55:33Z</dc:date>
    </item>
  </channel>
</rss>

