<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email alert not triggering in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755543#M12753</link>
    <description>&lt;P&gt;Or specifically - if the alert _is_ being triggered but there is a problem with email delivery, search for anything regarding sendemail.py&lt;/P&gt;</description>
    <pubDate>Sat, 15 Nov 2025 14:52:41 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-11-15T14:52:41Z</dc:date>
    <item>
      <title>Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755431#M12751</link>
      <description>&lt;P&gt;Hello, we have a DMC configured on Splunk Licence Master, I need to enable all the critical resource utilization alerts on DMC and send email notifications. I have configured the server setting under settings&amp;gt;server setting&amp;gt;Email settings and set up the same configurations as on our search head (which is successfuly generating email notifications) but the thing is, alerts are triggering but but I am not receiving any email notifications. can somebody help me to figure out the root cause?&lt;/P&gt;&lt;P&gt;Note: Network connectivity established between mail server and LM server.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 12:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755431#M12751</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-12T12:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755542#M12752</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;- Search for internal logs to understand and troubleshoot the issue further.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal NOT source=*_access* "&amp;lt;title of the alert&amp;gt;"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And see what logs tell you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote!!!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2025 08:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755542#M12752</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-11-15T08:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755543#M12753</link>
      <description>&lt;P&gt;Or specifically - if the alert _is_ being triggered but there is a problem with email delivery, search for anything regarding sendemail.py&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2025 14:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755543#M12753</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-15T14:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755575#M12754</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="maheshnc_0-1763380670341.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40827iFFB1976503E0826B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="maheshnc_0-1763380670341.png" alt="maheshnc_0-1763380670341.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Getting this error, not sure why&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 11:58:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755575#M12754</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-11-17T11:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755601#M12755</link>
      <description>&lt;P&gt;Well... this is something that should be troubleshot with your email admins because there is apparently something wrong with your Splunk trying to authenticate to the email server.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 17:01:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755601#M12755</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-17T17:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755624#M12756</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;, you might need to enable email relay from your DMC/LM server to Email server in order to send internal emails (as per your organizational policies.)&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 09:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755624#M12756</guid>
      <dc:creator>SK99</dc:creator>
      <dc:date>2025-11-18T09:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755643#M12757</link>
      <description>&lt;P&gt;I don't think you can "enable forwarding" on outlook com. You need to properly authenticate.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 19:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755643#M12757</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-18T19:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755646#M12758</link>
      <description>&lt;P&gt;Yes, with email relay there is option for "&lt;STRONG&gt;IP address authentication";&amp;nbsp;&lt;/STRONG&gt;means&amp;nbsp;&lt;SPAN&gt;to authorize a specific server's IP address to send email through the relay service.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 04:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755646#M12758</guid>
      <dc:creator>SK99</dc:creator>
      <dc:date>2025-11-19T04:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Email alert not triggering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755657#M12759</link>
      <description>&lt;P&gt;Interesting. Didn't expect that. But be aware that since you're most probably not using static public IPs on your Splunk components you'd be opening relaying from whatever is NAT-ed to the same IP.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 07:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Email-alert-not-triggering/m-p/755657#M12759</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-19T07:26:01Z</dc:date>
    </item>
  </channel>
</rss>

