Splunk Cloud Platform

Alert and reports not coming to mailbox

aravind
Observer

Hi,


We are experiencing a critical issue where several scheduled alerts/reports are not being received by intended recipients. This issue affects both individual mailboxes and distribution lists. Initially, only a few users reported missing alerts. However, it has now escalated, with all members of the distribution lists no longer receiving several key reports. Only a few support team members  continue to receive alerts in their personal mailboxes, suggesting inconsistent delivery.

Also just checking, is there is any suppression list blocking

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing would be to verify whether the scheduled searches were run in the first place. If they were and triggered alert actions, you should verify whether the emails were correctly sent (Ismo already provided links to other similar threads). Then you'll know where to start troubleshooting - if it's a Splunk issue because the mails weren't sent or if you need to search on the receiving end why they weren't delivered.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you look from splunk's internal logs if those alerts has working and try to send emails?

There are some links to old answers how you could try to figure out it.

After you have check those and look if you can find answer from those and it's still issue, please show what you have in your logs about those sendemail parts.

Quite often situation is that splunk has sent those alerts, but those are vanished in somewhere else.

0 Karma

aravind
Observer

can you share the  support mail address or any contacts.Because, i have tried to raise a ticket in support, but its failed.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @aravind 

There isnt a suppression list which customers can access, however if you log a support ticket they are able to check the PostMark mail server logs to check if any emails bounced, this could help confirm that 
a) If the alert actually fired correctly
b) Email accepted by the mail relay
c) If the relay had any issue sending on to the final destination.

At a previous customer we had a number of issues with the customer email server detecting some of the Splunk Cloud alerts as spam and silently bouncing them.

You can contact Support via https://www.splunk.com/support

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...