Alerting

Splunk stopped sending email alerts for some alerts

sheaross
Explorer

Splunk sending email alerts for some of my alerts not all of them.  I have scheduled alerts that run each day at specific times.  These alerts run the query at a runtime of 1-10 seconds.  Nothing has changed in the Splunk environment.  I run this command:  index=_* (ERR* OR FAIL* OR WARN* OR CANNOT) (email OR sendemail).  9 results are returned and I find this error.  ERROR:root:(452, '4.3.1 Insufficient system resources (UsedDiskSpace[E:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\data\\Queue])').

I've checked with IT and they stated there are no issues with the exchange server, but like I stated above some alerts work and others do not.  Any guidance you guys can provide would be great.

Labels (2)
Tags (1)

vikramyadav
Contributor

Hi @sheaross ,

Before checking any errors can you check whether your alert has been triggered or not?
You can check from  here http://yourserver:8000/en-US/alerts/search

If you can see your alert has been triggered and still you are not able to see the alert kindly let me know.

--------------------------------------------------------

If this helps your like will be appreciated 😊

sheaross
Explorer

Sorry about that, these are more reports than alerts.  These reports send an email at a scheduled time of the day.  Some work and some do not work.  I've looked at the Job Manager and these reports have been executed but some were not sent while others are sent.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...