Hi PickleRick, Thanks, 1) Yes, I have tried many thing, also by using the opposite condition: alert_condition = search mincount < 7 2) In all the logs I have checked (including sendemail.py, which does not log anything in my opinion) and searched, it is/was successful, status: success, not skipped or otherwise found to be delayed or ??? 3) example spl: index=_* AND alert_actions="email" | stats count by status Output: 42 Success over last 24h 02-17-2024 12:12:17.264 +0100 INFO SavedSplunker - savedsearch_id="nobody;search;Alert_trigger_1v1", search_type="scheduled", search_streaming=0, user="admin", app="search", savedsearch_name="Alert_trigger_1v1", priority=default, status=success, digest_mode=0, durable_cursor=0, scheduled_time=1708168200, window_time=0, dispatch_time=1708168333, run_time=0.142, result_count=1, alert_actions="email", sid="scheduler__admin__search__RMD5ea1ed26b5154d33f_at_1708168200_47", suppressed=0, fired=1, skipped=0, action_time_ms=3528, thread_id="AlertNotifierWorker-0", message="", workload_pool="" So no error message to be found sofar?? What do I miss here. Although I also searched in python.log and I found part of many messages: 2024-02-17 12:32:17,265 +0100 ERROR sendemail:572 - (554, b'5.2.252 SendAsDenied; ticket@eremote.nl not allowed to send as Splunk_eRemote@uBDC01; STOREDRV.Submission.Exception:SendAsDeniedException.MapiExceptionSendAsDenied; Failed to process message due to a permanent exception with message [BeginDiagnosticData]Cannot submit message. ....>> Splunk_eRemote@uBDC01; Splunk_eRemote is a textfield in SMPT-settings. Python code seems to append "@uBDC01" to it (is the hostname of my testserver ???) I can not make any sense out of it (same setting used in past 6 year?!) on our production server Again: Sendemail is working fine, in dashboard-search (form) and when using it for testing by running manual SPL code in searches Any thoughts? regards AshleyP
... View more