A real-time alert that looks for 0 events in the last N minutes does not seem to send any email. It does put entries in the triggered alerts log.
The alert contains this data:
trigger condition: "Number of Results is = 0 in 5 minutes."
processed customer=32323 sourcetype="splunktest-too_small"
We have another alert that triggers whenever "firealert" appears in the log. When I trigger that alert, I see `index=internal` log spewage of the form
... savedsearch_name="fire_alert", status=success, digest_mode=0, scheduled_time=1442592619, window_time=0, dispatch_time=1442592620, run_time=1830.371, result_count=1, alert_actions="email", ...
There is no similar line in the log when the first real-time alert is triggered.
can you add the config from savedsearches.conf? Maybe something is off with the email config. Are you able to use the send email action for any alerts at all?
hard to say. there may be something wrong w/the mail server or mail config.
try searching for: "index=_internal ERROR"
check your alert_actions.conf and make sure your either you have the correct username and passwrod or your SMTP is white listing you .