Splunk sending email alerts for some of my alerts not all of them. I have scheduled alerts that run each day at specific times. These alerts run the query at a runtime of 1-10 seconds. Nothing has changed in the Splunk environment. I run this command: index=_* (ERR* OR FAIL* OR WARN* OR CANNOT) (email OR sendemail). 9 results are returned and I find this error. ERROR:root:(452, '4.3.1Insufficientsystemresources (UsedDiskSpace[E:\\ProgramFiles\\Microsoft\\ExchangeServer\\V15\\TransportRoles\\data\\Queue])').
I've checked with IT and they stated there are no issues with the exchange server, but like I stated above some alerts work and others do not. Any guidance you guys can provide would be great.
Sorry about that, these are more reports than alerts. These reports send an email at a scheduled time of the day. Some work and some do not work. I've looked at the Job Manager and these reports have been executed but some were not sent while others are sent.