Alerting

Why is the email alert action not working for a scheduled search after moving the saved search to a different app?

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi Everyone!

I have an issue regarding scheduled Alerts.

Below defined saved search was configured in the Search app. It was working fine and triggered an email:

[Test Email Alert]
action.email = 1
action.email.format = table
action.email.inline = 1
action.email.reportServerEnabled = 0
action.email.sendresults = 1
action.email.to = xyz@gmail.com
action.keyindicator.invert = 0
alert.digest_mode = True
alert.expires = 1h
alert.suppress = 0
alert.track = 1
auto_summarize.dispatch.earliest_time = -1d@h
counttype = number of events
cron_schedule = */10 * * * *
dispatch.earliest_time = -10min@min
dispatch.latest_time = now
display.general.type = statistics
display.page.search.mode = verbose
display.page.search.tab = statistics
enableSched = 1
quantity = 0
relation = greater than
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = index=main host="127.0.0.1"

I can find the log of successful execution with the search below:

index=_internal source=*scheduler.log savedsearch_name="Test Email Alert" alert_actions=email

After this, I shifted this saved search to a different app (myapp) .

The saved search was scheduled and runs perfectly, but an email is not received. Using this search below, I cannot find any log of the search successfully executing.

index=_internal source=*scheduler.log savedsearch_name="Test Email Alert" alert_actions=email

But I found a log without alert_action, like this..

index=_internal source=*scheduler.log savedsearch_name="Test Email Alert" 

Kindly let me know if I am missing something.

Thanks .

0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi,
As I have resolved this issue with following conclusions.
The email configurations should be defined in alert_actions.conf at app level or system level.

In my case, email configurations are defined in alert_actions.conf of "search" app. So my savedsearch working proper in "search" app.
Then after I have moved (deleting and creating) savessearch from search app to new app "myapp". "myapp" and System level has no any email configurations in alert_actions.conf. So savedsearch executed properly but not sending any emails.

As a solution I have defined system level email configurations in alert_actions.conf. Now It's working as per expected.

Thanks

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi,
As I have resolved this issue with following conclusions.
The email configurations should be defined in alert_actions.conf at app level or system level.

In my case, email configurations are defined in alert_actions.conf of "search" app. So my savedsearch working proper in "search" app.
Then after I have moved (deleting and creating) savessearch from search app to new app "myapp". "myapp" and System level has no any email configurations in alert_actions.conf. So savedsearch executed properly but not sending any emails.

As a solution I have defined system level email configurations in alert_actions.conf. Now It's working as per expected.

Thanks

0 Karma

somesoni2
Revered Legend

How did you move the search to different app? Did you use the move option OR created an identical search in new app and deleted from original place? If it's former, then just open the search and save it (no changes required) and try.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi somesoni2,
Thanks for replying.
I had deleted from search app and created in my new app.
Thanks

0 Karma

gyslainlatsa
Motivator

hi kamlesh_vaghela,

go and modify the permissions for this savedsearch and select all apps for the rights write and read

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

hi gyslainlatsa,

thanks for answering.
Permission Given. But still same.

Is that any another issue ??

0 Karma

gyslainlatsa
Motivator

you also have to change the permissions the app myapp?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

hi gyslainlatsa,

app permission changed ..

But still same issue :(.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...