Splunk Enterprise

What could be the issue for not receiving the mail from alert?

Ash1
Communicator

We have setup one alert which should trigger for every 1 hour

When we run the alert query it is showing up the results but we did not received mail

There is no diff in index and event time

In scheduler logs it is showing status as success but i don't see python logs and alert did not get fired

 

What could be the issue for not receiving the mail from alert.

Labels (1)
Tags (1)
0 Karma

thahir
Contributor

Validate it through the below spl query

 

index=_internal | head 1 | sendemail to="name@my.email.domain" format="html" server=smtp.gmail.com:587 use_tls=1

 

0 Karma

thahir
Contributor

Have you Configured the smtp in the search head? 

Settings -> Server settings -> Email settings

0 Karma

bowesmana
SplunkTrust
SplunkTrust

If your alert has fired and has sent the email and it was not received, then look for any events in _internal

index=_internal sendemail

Is your Splunk server able to talk to the SMTP host it is trying to send email to - have you configured that server?

 

0 Karma

Ash1
Communicator

When i checked with index =_internal sendemail I don't see any logs

The email which we used to trigger alert is fine because every day alert triggers and we receive email this issue is happening suddenly like once in a week we are not receiving email

0 Karma

bowesmana
SplunkTrust
SplunkTrust

So you are saying sometimes you get the email and occasionally you do not get it.

Can you see examples of the sendemail in the internal logs for a successful email alert?

Do you have access to the _internal index?

0 Karma

Ash1
Communicator

Yes correct

And i saw the send email logs  for other alerts which I can see in internal logs. Looks good

But i don't see send email logs for this alert in internal logs 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...