Alerting

After configuring email alerts, why am I not receiving all emails from Splunk Enterprise?

varmamkm
New Member

I have configured triggered alerts & email alerts for an alert which runs every hour with custom count >0 with trigger for each result.

I see triggered alerts for every hour and i don't see any emails triggered for every hour. I get only one email in the morning and thats it..

Can you please help me figure out which configuration i should change so that i receive emails for every triggered alert?

0 Karma

burwell
SplunkTrust
SplunkTrust

Be sure that your Splunk instance had configuration to send to your mailserver

In /opt/splunk/etc/system/local/alert_actions.conf

[email]
from       = splunk@mydomain.com
mailserver = myserver.mydomain:25
0 Karma

harishalipaka
Motivator

@varmamkm

can u check your scheduled time .put it cron schedule make it * * * * * it will run every one minute

Thanks
Harish
0 Karma

jlelli
Path Finder

As @harishalipaka said: change the scheduled time on Cron; the expression for "every hour" is: 0 0 * ? * *

0 Karma

varmamkm
New Member

I have tried both (cron & run every hour) options but no luck.. i see them triggered and logged under "Activity->Triggered Alerts" but it is not triggering emails

0 Karma

harishalipaka
Motivator
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...