Alerting

Alert not working

trueclicks
Explorer

Hi,

easy alert ( see bellow ) is not working.
alt text

Condition meets the criteria.

alt text

  • Mail Server Settings are set by default ( spunk little).
  • Alert is triggered
  • Mail is not sent.
  • Alert action is empty. Why ?

Do I do something wrong ? or is it bug ?

Thanks for answers / ideas / recommendations.

0 Karma
1 Solution

hardikJsheth
Motivator

From the screen shot splunk2.png, it looks like that when the alert run it did not return any result. That's why you have result_count="0" and alert_action="".

Please check if you are getting the results. Also check the condition of your scheduled search, on what condition do you fire an alert.

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi trueclicks,
I assume that you verified that your system correctly sends eMails.
Sometimes the problem is that the results are too large for the eMail body or the eMail attachment so the eMail is blocked by the mail server.
So verify unflagging attachment and results in the eMail Body.
Bye.
Giuseppe

0 Karma

trueclicks
Explorer

Thank you for your help.

0 Karma

hardikJsheth
Motivator

From the screen shot splunk2.png, it looks like that when the alert run it did not return any result. That's why you have result_count="0" and alert_action="".

Please check if you are getting the results. Also check the condition of your scheduled search, on what condition do you fire an alert.

trueclicks
Explorer

Thank you. Problem was in my scheduled search. I wanted to fire event when the search did not have any result.
This helped:
https://answers.splunk.com/answers/127905/set-count-to-0-if-no-results-found-in-splunk-alert.html

0 Karma

dkoshe_splunk
Splunk Employee
Splunk Employee
0 Karma

trueclicks
Explorer

Thank you for you help.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...