Greetings!
I have a scheduled rule that runs every closed minute and it matched an event at 1:30:03PM which was supposed to send an email but it hasn't. What could be the cause of this?
Any suggestions will be appreciated
Hi @jveloso did you checked and confirmed that there is no email action fired from Splunk when this alert fired at the mentioned instanc, you can use below query to confirm if there was no matching event for the issue timeframe that would imply email was not sent when the alert fired.
index=_internal sourcetype=scheduler status=success savedsearch_name=<name of your alert> alert_action=email