Alerting

Unable to generate email alerts in splunk 6.0.1

balajsoz
Path Finder

Hi,
am using the splunk 6.0.1 60days enterprise trial version and have created a search called "IE-Alert" to trigger a alert whenever people opens up the Internet explorer in my local desktop.

And splunk also running in local desktop only.

Now i have updated the EMAIL ALERT SETTINGS under SETTINGS tab with Mail Host as proxy2.w1.com, username as "bjsoz" which is my username to log in my local office desktop and with the password.

I entered the same passwords also in this settings.

But still am not getting any email alerts even after i updated the setup of actions in alert genrations.

please help.

Also suggest how to setup the email setting for sending alert to my personal id which in gmail.com

Tags (2)
0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

How many real time searches are you running? How about how many cpu's are on that box?

0 Karma

yannK
Splunk Employee
Splunk Employee

check in the scheduler log to see if the alert triggered
$SPLUNK_HOME/var/log/splunk/scheduler.log

check the internal log for errors, the email script report in it.
$SPLUNK_HOME/var/log/splunk/python.log

A classic problem is that your mail server is refusing the connection, because of ip whitelist.

PS you can use splunk for that with index=_internal host=mysearchhead source=*/myfile.log

balajsoz
Path Finder

Hi yannk,

Thanks for the suggestion.
In scheduler.log, it showing the alerts perfectly.
And I have checked the python log and seen this below error and it comes continously whenevr alert trying to send email;
-> 2014-02-11 10:40:42,437 IST ERROR sendemail:357 - Sending email. subject="Splunk Alert: IE-ALERT-TEST;", results_link="http://localhost:8000/app/search/search?q=%7Cloadjob%20rt_scheduler__admin__search__RMD5fbb3cdb7aa7a...", recipients="['balaji.sozharajan@wipro.com']"
Please advice.

0 Karma

antlefebvre
Communicator

What is the backend mail server you are running? Are you the admin or is there another person responsible? I would suggest you ask if they can set up a service account to email from.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...