Alerting

After configuring email alerts, why am I not receiving all emails from Splunk Enterprise?

varmamkm
New Member

I have configured triggered alerts & email alerts for an alert which runs every hour with custom count >0 with trigger for each result.

I see triggered alerts for every hour and i don't see any emails triggered for every hour. I get only one email in the morning and thats it..

Can you please help me figure out which configuration i should change so that i receive emails for every triggered alert?

0 Karma

burwell
SplunkTrust
SplunkTrust

Be sure that your Splunk instance had configuration to send to your mailserver

In /opt/splunk/etc/system/local/alert_actions.conf

[email]
from       = splunk@mydomain.com
mailserver = myserver.mydomain:25
0 Karma

harishalipaka
Motivator

@varmamkm

can u check your scheduled time .put it cron schedule make it * * * * * it will run every one minute

Thanks
Harish
0 Karma

jlelli
Path Finder

As @harishalipaka said: change the scheduled time on Cron; the expression for "every hour" is: 0 0 * ? * *

0 Karma

varmamkm
New Member

I have tried both (cron & run every hour) options but no luck.. i see them triggered and logged under "Activity->Triggered Alerts" but it is not triggering emails

0 Karma

harishalipaka
Motivator
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...