<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing some Real-Time emails in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Missing-some-Real-Time-emails/m-p/141419#M3153</link>
    <description>&lt;P&gt;Recently a real-time search and email alert has failed to fire consistently. I am fairly certain that this used to work for every event. Now for some real-time triggered events, no email is getting sent. I compare the splunk search to the emails I'm getting and I am definitely missing emails. The search string has not changed. Perhaps it's a performance issue? (I am using a JOIN but my splunk admin tells me the system has plenty of resources).  I am mostly curious about how to troubleshoot something like this. Thank you. &lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2015 14:35:16 GMT</pubDate>
    <dc:creator>jat75</dc:creator>
    <dc:date>2015-06-03T14:35:16Z</dc:date>
    <item>
      <title>Missing some Real-Time emails</title>
      <link>https://community.splunk.com/t5/Reporting/Missing-some-Real-Time-emails/m-p/141419#M3153</link>
      <description>&lt;P&gt;Recently a real-time search and email alert has failed to fire consistently. I am fairly certain that this used to work for every event. Now for some real-time triggered events, no email is getting sent. I compare the splunk search to the emails I'm getting and I am definitely missing emails. The search string has not changed. Perhaps it's a performance issue? (I am using a JOIN but my splunk admin tells me the system has plenty of resources).  I am mostly curious about how to troubleshoot something like this. Thank you. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2015 14:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Missing-some-Real-Time-emails/m-p/141419#M3153</guid>
      <dc:creator>jat75</dc:creator>
      <dc:date>2015-06-03T14:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Missing some Real-Time emails</title>
      <link>https://community.splunk.com/t5/Reporting/Missing-some-Real-Time-emails/m-p/141420#M3154</link>
      <description>&lt;P&gt;Update: I created the same real time alert without using a join (however I do need a join) and I am getting more emails for that alert than the one with the join. Could this be a timing or resource thing?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2015 12:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Missing-some-Real-Time-emails/m-p/141420#M3154</guid>
      <dc:creator>jat75</dc:creator>
      <dc:date>2015-06-12T12:56:44Z</dc:date>
    </item>
  </channel>
</rss>

