Splunk Cloud Platform

Alert and reports not coming to mailbox

aravind
Observer

Hi,


We are experiencing a critical issue where several scheduled alerts/reports are not being received by intended recipients. This issue affects both individual mailboxes and distribution lists. Initially, only a few users reported missing alerts. However, it has now escalated, with all members of the distribution lists no longer receiving several key reports. Only a few support team members  continue to receive alerts in their personal mailboxes, suggesting inconsistent delivery.

Also just checking, is there is any suppression list blocking

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing would be to verify whether the scheduled searches were run in the first place. If they were and triggered alert actions, you should verify whether the emails were correctly sent (Ismo already provided links to other similar threads). Then you'll know where to start troubleshooting - if it's a Splunk issue because the mails weren't sent or if you need to search on the receiving end why they weren't delivered.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you look from splunk's internal logs if those alerts has working and try to send emails?

There are some links to old answers how you could try to figure out it.

After you have check those and look if you can find answer from those and it's still issue, please show what you have in your logs about those sendemail parts.

Quite often situation is that splunk has sent those alerts, but those are vanished in somewhere else.

0 Karma

aravind
Observer

can you share the  support mail address or any contacts.Because, i have tried to raise a ticket in support, but its failed.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @aravind 

There isnt a suppression list which customers can access, however if you log a support ticket they are able to check the PostMark mail server logs to check if any emails bounced, this could help confirm that 
a) If the alert actually fired correctly
b) Email accepted by the mail relay
c) If the relay had any issue sending on to the final destination.

At a previous customer we had a number of issues with the customer email server detecting some of the Splunk Cloud alerts as spam and silently bouncing them.

You can contact Support via https://www.splunk.com/support

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...