Alerting

How to troubleshoot why one of our users is not receiving email alerts from Splunk?

Kaushikkatta03
Explorer

This is one of the example email alerts:


Saved search results. 

Name: 'Cisco - Level 3 Internet BGP Drops (dcinternet02r)' 
Query Terms: 'source=\"/var/log/syslog_info\" _raw=*\"%BGP-5-ADJCHANGE: neighbor 4.15.168.57\"* earliest=-36hr@h | table _time, _raw | sort -_time' 
Link to results: https://splunk.********.com/
sid=scheduler__hfmra200__search__RMD5ce14eefd70aff3f9_at_1459853760_15001 
Alert was triggered because of: 'Saved Search [Cisco - Level 3 Internet BGP Drops (dcinternet02r)]: always(0)' 
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify the user's email address is correct in the alert.
Ask the user to check his spam folder and mail filters.

---
If this reply helps you, Karma would be appreciated.

Kaushikkatta03
Explorer

Everything are good , from there side email address and he check in spam fold. He haven't received any mails.

And if i try to run commands under the applications which are in saved search, like:

source=\"/var/log/syslog_info\" _raw=\"%BGP-5-ADJCHANGE: neighbor 4.15.168.57\" earliest=-36hr@h | table _time, _raw | sort -time 

I cant see any data . "No data found "

0 Karma

pradeepkumarg
Influencer

Is he the only recipient for the alert? If so, check sourcetype = python_log logs for any errors in sending email. If there are other recipients for the alert check with them to see if they got the email and you can validate the to distribution list from that email

0 Karma

pradeepkumarg
Influencer

Sorry, I didn't realize python logs are not indexed by default and you have to specifically index them. But you can find them here $SPLUNK_HOME/var/log/splunk/python.log

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...