I changed alert_actions.conf [email] in an app that is pushed to the Search Head Cluster by the deployer which initiated a rolling restart.
The rolling restart killed a search my boss was running and through some index congestion warnings.
Is this expected, or should I file a bug? Using Splunk 6.3.0
Did you file a case on this ? The default for a restart appears to be a non-graceful restart of the cluster when applying a new cluster bundle or a rolling restart.
I have raised an enhancement request for this feature. I had a case where a alert was running and 1 of 2 actions had fired before the restart kicked in, resulting in confusion for the user who did not receive the alert via email (which was the 2nd action)