Hello,
I don't receive any email notification from splunk , while the logs of scheduler show that my saved search is triggered:
SPLUNK_HOME = /opt/splunk
cd /opt/splunk/var/log
tail –f splunk_access.log
127.0.0.1 - splunk-system-user [15/Apr/2013:06:33:03.580 -0400] "POST /servicesNS/nobody/wmoperationalintelligence/saved/searches/Errors%20throwing%20on%20online/notify?trigger.condition_state=1 HTTP/1.0" 200 256 - - - 3ms
tail –f scheduler.log
04-15-2013 06:36:03.441 -0400 INFO SavedSplunker - savedsearch_id="nobody;wmoperationalintelligence;Errors throwing on online", user="nobody", app="wmoperationalintelligence", savedsearch_name="Errors throwing on online", status=success, digest_mode=1, scheduled_time=1366022160, dispatch_time=1366022161, run_time=2.146, result_count=9, alert_actions="", sid="scheduler_nobodywmoperationalintelligence_RMD55e2f9a9d4e6ff98b_at_1366022160_142", suppressed=0, thread_id="AlertNotifierWorker-0"
tail –f python.log
No error in python.log
tail –f web_access.log
10.10.10.94 - admin [15/Apr/2013:06:39:46.916 -0400] "GET /en-US/api/messages/index HTTP/1.1" 200 341 "http://192.168.1.20:8000/en-US/app/wmoperationalintelligence/job_management?savedSearch=Errors%20thr..." "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.64 Safari/537.31" - 516bd8f2ea4aa0610 9ms
Any idea how to fix this?
Thanks
I hope it will help you.