Hi,
easy alert ( see bellow ) is not working.
Condition meets the criteria.
Do I do something wrong ? or is it bug ?
Thanks for answers / ideas / recommendations.
From the screen shot splunk2.png, it looks like that when the alert run it did not return any result. That's why you have result_count="0" and alert_action="".
Please check if you are getting the results. Also check the condition of your scheduled search, on what condition do you fire an alert.
Hi trueclicks,
I assume that you verified that your system correctly sends eMails.
Sometimes the problem is that the results are too large for the eMail body or the eMail attachment so the eMail is blocked by the mail server.
So verify unflagging attachment and results in the eMail Body.
Bye.
Giuseppe
Thank you for your help.
From the screen shot splunk2.png, it looks like that when the alert run it did not return any result. That's why you have result_count="0" and alert_action="".
Please check if you are getting the results. Also check the condition of your scheduled search, on what condition do you fire an alert.
Thank you. Problem was in my scheduled search. I wanted to fire event when the search did not have any result.
This helped:
https://answers.splunk.com/answers/127905/set-count-to-0-if-no-results-found-in-splunk-alert.html
Hello,
Have you looked into splunk logs to find out if there is an error in sending emails?
Also there are a lot of answers queries around troubleshooting emails not getting sent.
See for example:
https://answers.splunk.com/answers/330817/how-to-troubleshoot-why-im-not-getting-email-alert.html
https://answers.splunk.com/answers/32498/how-to-troubleshoot-splunk-email-notification.html
https://answers.splunk.com/answers/221223/how-to-troubleshoot-why-i-am-not-receiving-emails.html
https://answers.splunk.com/answers/225648/alert-email-not-being-sent.html
Hope this helps.
-Dhananjay
Thank you for you help.