Alerting

How do you enable email alerts in the trial version of Splunk Enterprise?

sureshkrovi
Explorer

Hi ,

Just wanted to check if there is a way to get email alerts enabled in the Splunk Enterprise trial version. I see emails are not getting triggered and I wanted to check if this could be done in any other way.

Thanks,

0 Karma
1 Solution

vinkumar_splunk
Splunk Employee
Splunk Employee

I guess you didn't set up the email configuration, go through the below link and configure it:

http://docs.splunk.com/Documentation/Splunk/7.2.1/Alert/Emailnotification

If you're still facing the issue, then look for python.log under splunk_home/var/log/splunk dir, which contains information about it. Look for "sendemail"

View solution in original post

0 Karma

vinkumar_splunk
Splunk Employee
Splunk Employee

I guess you didn't set up the email configuration, go through the below link and configure it:

http://docs.splunk.com/Documentation/Splunk/7.2.1/Alert/Emailnotification

If you're still facing the issue, then look for python.log under splunk_home/var/log/splunk dir, which contains information about it. Look for "sendemail"

0 Karma

sureshkrovi
Explorer

Thanks you for pointing out .I've realized some steps to be taken when I used open source smtp servers that blocks messages by stating less secured application are blocked to use smtp server.All good once I enabled access to splunk

0 Karma

Shan
Builder

@sureshkrovi,

Splunk enterprise trial version is enabled with alert option. Sure you can able to send email alert. Can you please let me know what is the error your getting ..

Thanks ..

0 Karma

sureshkrovi
Explorer

I don't think I've errors,It just not sending email.Here are the configurations if it helps.Please note that I can see notifications if I switched alert type and believe that endorse issue with email trigger.Please let me know if you need more details.
Enabled:
Yes. Disable
App:
search
Permissions:
Shared Globally. Owned by admin. Edit
Modified:
Nov 16, 2018 12:44:30 PM
Alert Type:
Scheduled. Hourly, at 45 minutes past the hour. Edit
Trigger Condition:
Number of Results is > 0. Edit
Actions:
1 Action
Alert iconSend email
Edit

0 Karma

adonio
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...