Alerting

Several rules not sending email alert

jerm1020rq
Explorer

I am experiencing an issue where the rules in place are firing as expected but have suddenly the past 2 weeks stopped sending email alerts. while this wouldnt be difficult to troubleshoot if it was ALL alerts, its only a select few. The configuration of the email alerts are the same as the alerts that are working and emailing as expected. Has anyone experienced this issue before?

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you share a working and non working alerts from savedsearches.conf?
0 Karma

jerm1020rq
Explorer

I will work on grabbing some of those and sharing.  I do want to add that other alerts send just fine and that this just starting happening out of nowhere it no changes made 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!