Hoping someone can help as I'm relatively new to Splunk On-Call administration. When our system sends an alert to multiple Splunk On-Call email addresses to contact and use multiple routing keys, the system only uses the first routing key in the list of recipients and drops everything else. For example, if I sent an email to
00000000+RoutingKey1@alert.victorops.com; 00000000+RoutingKey2@alert.victorops.com
Splunk On-Call will create an alert for RoutingKey1 but no alerts are created for RoutingKey2.
Is there an Alert Rule syntax that will extract these so it creates alerts for both?
Thanks.