Other Usage

Why is Splunk alert not firing email?

izzie123
Path Finder

Hello,

I have set an alert which generates around 50-60 events everyday. I have configured this alert to send mails to my email id, I have been observing that not all events generate emails and the count of the alert events and the mails received mismatches.

The alert mail is not fired intermittently. Can you please suggest some ways to troubleshoot the cause of this problem?

Thanks in advance

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you should look from _internal have those fired and if what has happened to them. You should also remember that email isn’t 100% sure delivery method.

Here are some links to this issue:

r. Ismo

0 Karma

izzie123
Path Finder

Thanks for your answer @isoutamo 
I checked the internal logs and found this error : 

ERROR:root:(421, b'4.4.2 Message submission rate for this client has exceeded the configured limit',")

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Your splunk server has sent too many alert emails in short period so smtp server refused to accept more. Are you sure that you don’t sent own alert per event instead of one email per running the alert?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...