Hi,
am using the splunk 6.0.1 60days enterprise trial version and have created a search called "IE-Alert" to trigger a alert whenever people opens up the Internet explorer in my local desktop.
And splunk also running in local desktop only.
Now i have updated the EMAIL ALERT SETTINGS under SETTINGS tab with Mail Host as proxy2.w1.com, username as "bjsoz" which is my username to log in my local office desktop and with the password.
I entered the same passwords also in this settings.
But still am not getting any email alerts even after i updated the setup of actions in alert genrations.
please help.
Also suggest how to setup the email setting for sending alert to my personal id which in gmail.com
How many real time searches are you running? How about how many cpu's are on that box?
check in the scheduler log to see if the alert triggered
$SPLUNK_HOME/var/log/splunk/scheduler.log
check the internal log for errors, the email script report in it.
$SPLUNK_HOME/var/log/splunk/python.log
A classic problem is that your mail server is refusing the connection, because of ip whitelist.
PS you can use splunk for that with index=_internal host=mysearchhead source=*/myfile.log
Hi yannk,
Thanks for the suggestion.
In scheduler.log, it showing the alerts perfectly.
And I have checked the python log and seen this below error and it comes continously whenevr alert trying to send email;
-> 2014-02-11 10:40:42,437 IST ERROR sendemail:357 - Sending email. subject="Splunk Alert: IE-ALERT-TEST;", results_link="http://localhost:8000/app/search/search?q=%7Cloadjob%20rt_scheduler__admin__search__RMD5fbb3cdb7aa7a...", recipients="['balaji.sozharajan@wipro.com']"
Please advice.
What is the backend mail server you are running? Are you the admin or is there another person responsible? I would suggest you ask if they can set up a service account to email from.