Alerting

After configuring email alerts, why am I not receiving all emails from Splunk Enterprise?

varmamkm
New Member

I have configured triggered alerts & email alerts for an alert which runs every hour with custom count >0 with trigger for each result.

I see triggered alerts for every hour and i don't see any emails triggered for every hour. I get only one email in the morning and thats it..

Can you please help me figure out which configuration i should change so that i receive emails for every triggered alert?

0 Karma

burwell
SplunkTrust
SplunkTrust

Be sure that your Splunk instance had configuration to send to your mailserver

In /opt/splunk/etc/system/local/alert_actions.conf

[email]
from       = splunk@mydomain.com
mailserver = myserver.mydomain:25
0 Karma

harishalipaka
Motivator

@varmamkm

can u check your scheduled time .put it cron schedule make it * * * * * it will run every one minute

Thanks
Harish
0 Karma

jlelli
Path Finder

As @harishalipaka said: change the scheduled time on Cron; the expression for "every hour" is: 0 0 * ? * *

0 Karma

varmamkm
New Member

I have tried both (cron & run every hour) options but no luck.. i see them triggered and logged under "Activity->Triggered Alerts" but it is not triggering emails

0 Karma

harishalipaka
Motivator
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...