Splunk Cloud Platform

Alert and reports not coming to mailbox

aravind
Observer

Hi,


We are experiencing a critical issue where several scheduled alerts/reports are not being received by intended recipients. This issue affects both individual mailboxes and distribution lists. Initially, only a few users reported missing alerts. However, it has now escalated, with all members of the distribution lists no longer receiving several key reports. Only a few support team members  continue to receive alerts in their personal mailboxes, suggesting inconsistent delivery.

Also just checking, is there is any suppression list blocking

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing would be to verify whether the scheduled searches were run in the first place. If they were and triggered alert actions, you should verify whether the emails were correctly sent (Ismo already provided links to other similar threads). Then you'll know where to start troubleshooting - if it's a Splunk issue because the mails weren't sent or if you need to search on the receiving end why they weren't delivered.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you look from splunk's internal logs if those alerts has working and try to send emails?

There are some links to old answers how you could try to figure out it.

After you have check those and look if you can find answer from those and it's still issue, please show what you have in your logs about those sendemail parts.

Quite often situation is that splunk has sent those alerts, but those are vanished in somewhere else.

0 Karma

aravind
Observer

can you share the  support mail address or any contacts.Because, i have tried to raise a ticket in support, but its failed.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @aravind 

There isnt a suppression list which customers can access, however if you log a support ticket they are able to check the PostMark mail server logs to check if any emails bounced, this could help confirm that 
a) If the alert actually fired correctly
b) Email accepted by the mail relay
c) If the relay had any issue sending on to the final destination.

At a previous customer we had a number of issues with the customer email server detecting some of the Splunk Cloud alerts as spam and silently bouncing them.

You can contact Support via https://www.splunk.com/support

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...