I am trying the following search to send email but encounters error message in python.log indicating "[Errno 10061] No connection could be made because the target machine actively refused it while sending mail to: temp@domain.com".
Also tried saving search as alert and indicated email address but also got the above error message.
temperature sourcetype=kaa | rex field=_raw "\"endpointKeyHash\":\{\"string\":\"(?<endpoint>[^\"]*)\".*\"Event\": (?<mydata>\{.*\})\}$"| spath input=mydata | table _time, endpoint, temperature | eval threshold = 50 | where temperature > threshold | sendemail to=tzewei_79@yahoo.com.sg sendresults=true
May I know what other settings I need to do at this point? Please help.
Hi wuming79,
this sounds like trouble/problems outside of Splunk.
Check there is no firewall blocking SMTP from your Splunk server, check that the mail server you are using (Windows defaults as well to localhost and has most likely not any email sending facility by default) is allowing you to relay emails.
All your friendly network and email admin to check this for you.
Hope this helps ...
cheers, MuS
May I know how I can if my firewall is blocking SMTP from splunk server? Am I supposed to look inside Advanced settings?
Does alert works if the free trial expires? I'm trying this from home network and still see the same problem.
No, if the free trail license has expired alerting will stop because its not available - see the docs for more details http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree?r=searchtip#What_is_inc...
Ask your sysadmin or network admin for help. This is not something that can be configured in Splunk.
But a good starting point is this here https://www.port25.com/how-to-check-an-smtp-connection-with-a-manual-telnet-session-2/
cheers, MuS