Reporting

Missing some Real-Time emails

jat75
Explorer

Recently a real-time search and email alert has failed to fire consistently. I am fairly certain that this used to work for every event. Now for some real-time triggered events, no email is getting sent. I compare the splunk search to the emails I'm getting and I am definitely missing emails. The search string has not changed. Perhaps it's a performance issue? (I am using a JOIN but my splunk admin tells me the system has plenty of resources). I am mostly curious about how to troubleshoot something like this. Thank you.

Tags (2)
0 Karma

jat75
Explorer

Update: I created the same real time alert without using a join (however I do need a join) and I am getting more emails for that alert than the one with the join. Could this be a timing or resource thing?

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...