Alerting

Unable to generate email alerts in splunk 6.0.1

balajsoz
Path Finder

Hi,
am using the splunk 6.0.1 60days enterprise trial version and have created a search called "IE-Alert" to trigger a alert whenever people opens up the Internet explorer in my local desktop.

And splunk also running in local desktop only.

Now i have updated the EMAIL ALERT SETTINGS under SETTINGS tab with Mail Host as proxy2.w1.com, username as "bjsoz" which is my username to log in my local office desktop and with the password.

I entered the same passwords also in this settings.

But still am not getting any email alerts even after i updated the setup of actions in alert genrations.

please help.

Also suggest how to setup the email setting for sending alert to my personal id which in gmail.com

Tags (2)
0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

How many real time searches are you running? How about how many cpu's are on that box?

0 Karma

yannK
Splunk Employee
Splunk Employee

check in the scheduler log to see if the alert triggered
$SPLUNK_HOME/var/log/splunk/scheduler.log

check the internal log for errors, the email script report in it.
$SPLUNK_HOME/var/log/splunk/python.log

A classic problem is that your mail server is refusing the connection, because of ip whitelist.

PS you can use splunk for that with index=_internal host=mysearchhead source=*/myfile.log

balajsoz
Path Finder

Hi yannk,

Thanks for the suggestion.
In scheduler.log, it showing the alerts perfectly.
And I have checked the python log and seen this below error and it comes continously whenevr alert trying to send email;
-> 2014-02-11 10:40:42,437 IST ERROR sendemail:357 - Sending email. subject="Splunk Alert: IE-ALERT-TEST;", results_link="http://localhost:8000/app/search/search?q=%7Cloadjob%20rt_scheduler__admin__search__RMD5fbb3cdb7aa7a...", recipients="['balaji.sozharajan@wipro.com']"
Please advice.

0 Karma

antlefebvre
Communicator

What is the backend mail server you are running? Are you the admin or is there another person responsible? I would suggest you ask if they can set up a service account to email from.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...