<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor SMTP failures in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747829#M3853</link>
    <description>&lt;P&gt;im looking for a solution that i will be able to monitor if emails stopped receiving , not for troubleshoot for specific issue&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jun 2025 16:02:19 GMT</pubDate>
    <dc:creator>sarit_s6</dc:creator>
    <dc:date>2025-06-11T16:02:19Z</dc:date>
    <item>
      <title>monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747811#M3848</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I'm trying to monitor SMTP failures in my Splunk cloud environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know for sure that at some date we had problem and did not receive any emails but when im running this query :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sendemail source="/opt/splunk/var/log/splunk/python.log"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see any errors.&amp;nbsp;&lt;BR /&gt;How can I achieve my goal ?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 12:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747811#M3848</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-11T12:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747812#M3849</link>
      <description>&lt;P&gt;If there are no errors on Splunk's end then your email provider should be contacted to find out why the messages were not delivered.&amp;nbsp; It's possible the message were treated as spam or there was another problem that prevented delivery.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 12:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747812#M3849</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-06-11T12:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747813#M3850</link>
      <description>&lt;P&gt;we know for sure that Splunk had issue with sending emails during this time so for sure its in splunk's end&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 12:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747813#M3850</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-11T12:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747814#M3851</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260281"&gt;@sarit_s6&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SMTP logs arent directly logged into your Splunk Cloud environment, however if you log a support ticket they are able to check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Splunk-is-not-sending-mails-that-weight-more-than-10MB-of-data-native-SMTP-Splunk-limit#:~:text=Postmark%2C%20Splunk%20relay%20service" target="_self" rel="nofollow noopener noreferrer"&gt;PostMark&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;mail server logs to check if any emails bounced, this could help confirm that&amp;nbsp;&lt;BR /&gt;a) If the alert actually fired correctly from Splunk&lt;BR /&gt;b) Email accepted by the mail relay&lt;BR /&gt;c) If the relay had any issue sending on to the final destination.&lt;/P&gt;&lt;P&gt;At a previous customer we had a number of issues with the customer email server detecting some of the Splunk Cloud alerts as spam and silently bouncing them.&lt;/P&gt;&lt;P&gt;You can contact Support via&amp;nbsp;&lt;A href="https://www.splunk.com/support" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.splunk.com/support&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-unicode-emoji"&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 12:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747814#M3851</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-11T12:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747826#M3852</link>
      <description>&lt;P&gt;You can try to send email and then check those events from internal&lt;/P&gt;&lt;P&gt;1st send email e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd
| head 1
| sendemail to="your.email@your.domain" subject="testing"&lt;/LI-CODE&gt;&lt;P&gt;After that you should get at least this event from internal&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal  sourcetype=splunk_python sendemail source="/opt/splunk/var/log/splunk/python.log"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Of course it needs that your previous command has worked w/o issues.&lt;/P&gt;&lt;P&gt;It needs also access to _internal logs. There could be also need for some capabilities to send email.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 15:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747826#M3852</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-06-11T15:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747829#M3853</link>
      <description>&lt;P&gt;im looking for a solution that i will be able to monitor if emails stopped receiving , not for troubleshoot for specific issue&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 16:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747829#M3853</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-11T16:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747830#M3854</link>
      <description>&lt;P&gt;im getting the log&lt;BR /&gt;all the logs are in level INFO&lt;BR /&gt;I know for sure that splunk had an issue with sending emails at specific time but i cannot see any logs in _internal&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 16:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747830#M3854</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-11T16:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747833#M3855</link>
      <description>&lt;P&gt;Have you tried my examples? If you can send email and you have access those internal logs then there are at least one log line. If you cannot see those then you haven't have access to those logs to see it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2025-06-11 18:39:08,616 +0300 INFO	sendemail:275 - Sending email. sid=1749656347.70143, subject="testing", encoded_subject="testing", results_link="None", recipients="['your.email@your.domain']", server="localhost"&lt;/LI-CODE&gt;&lt;P&gt;How you are sure that the issue is with splunk? Have you some logs which shows that e.g. alert is fired and it has try to send it via sendemail? For that reason I suggest 1st check that sending email is working and after that start to look why your alerts are not sending it. And quite often then the reason was that alert hasn't fired.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 16:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747833#M3855</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-06-11T16:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747864#M3856</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I know for sure that its Splunk end because Splunk told us that they had issue with sending emails&lt;/P&gt;&lt;P&gt;Im getting the logs after running your example&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 06:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747864#M3856</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-12T06:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747876#M3857</link>
      <description>&lt;P&gt;When you say that its a problem at Splunk end, do you mean with Splunk's relay server or within your own cloud environment? SplunkCloud sends emails to a local relay before being sent out of Splunk's infrastructure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if your alerts fired successfully, it may not show errors sending the emails in your Splunk _internal logs because the failure happens between Splunkd (your actual Splunk process) and an external dependency.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I said, Splunk Support should be able to access their relay logs and validate where the issue is coming from, but either way - it is not possible for you to directly monitor for failures against the remote SMTP service, you might see some errors if your instance is unable to reach the local relay but also not guaranteed. I wasnt able to find any Splunk apps which monitor the local SMTP connection directly.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 08:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747876#M3857</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-12T08:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747877#M3858</link>
      <description>You have already case open and ongoing with splunk support, so what you expecting that we can offer to you especially you didn't told this to us?</description>
      <pubDate>Thu, 12 Jun 2025 09:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747877#M3858</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-06-12T09:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747961#M3859</link>
      <description>&lt;P&gt;I want to monitor such behavior myself and not count on Splunk to update me when such thing is happening&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jun 2025 08:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747961#M3859</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2025-06-15T08:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: monitor SMTP failures</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747965#M3860</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260281"&gt;@sarit_s6&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I understand, unfortunately access to the relay logs is not possible.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jun 2025 12:02:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/monitor-SMTP-failures/m-p/747965#M3860</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-15T12:02:50Z</dc:date>
    </item>
  </channel>
</rss>

