There isn't much to go with here, but here are some trouble-shooting tips you can use.
Enable Message Tracking on your Exchange server that is receiving the alert and ensure it is being processed properly
Enable SMTP Transport Logging and see what is actually going on
IN general, Exchange requires authentication - put in an exception for your Splunk server in the hub transport
Let me know if any of that helps.
... View more