Hello splunkers,
Please help me to figure out this issue!
I have a realtime alert which triggers an alert and send the email to users.
when i ingest 62 files in splunk index, triggered alerts are 52 but i have received only 44 email notifications only.
I figured out that the first email was received at 20:35 and 44th email at 20:40 and not received any further.
I have also tried changing these two parameters of alert from there default value 5m,
1. action.email.maxtime-->1800
2. action.script.maxtime-->1800
splunk enterprise v6.6.3
Please help me if any other parameter is to be changed, or any known issue like this.
What kind of information are you sending your users in email, if you are using inline table in email body you might have an issue with large number of rows. Alternatively use this SPL: index=_internal sendemail and try to find root cause.
Hi,
I have tried query "index=_internal sourcetype=splunk_python" and the results are same as the number of emails i have received.