<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alerts in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684604#M15932</link>
    <description>&lt;P&gt;Also , i have the following error which is generated for only one previous alert , if you could please look and see what other steps I can take , if that helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-04-18 05:18:47,938 +0000 ERROR sendemail:187 - Sending email. subject="Splunk Alert: ITSEC_Backup_Change_Alert", encoded_subject="Splunk Alert: ITSEC_Backup_Change_Alert", results_link="*****", recipients="['it-security@durr.com']", server="********"&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2024 06:02:12 GMT</pubDate>
    <dc:creator>shakti</dc:creator>
    <dc:date>2024-04-18T06:02:12Z</dc:date>
    <item>
      <title>Cannot send email alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684194#M15925</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing same issue as you ...I am not receiving email alerts from splunk ....Instead of localhost what name should I kept for&amp;nbsp; mail server host name?&amp;nbsp; Could you please suggest&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 18:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684194#M15925</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-20T18:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684196#M15926</link>
      <description>&lt;P&gt;Which email provider are you planning to use? Do you have your own email server, or are you using gmail or another online email service?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Apr 2024 18:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684196#M15926</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-14T18:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684206#M15927</link>
      <description>&lt;P&gt;I am using outlook as the external mail server ..Do you have any idea what value should I use in that mail server hostname?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 04:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684206#M15927</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-15T04:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684285#M15928</link>
      <description>&lt;P&gt;As in outlook.com ? If so, there is an article here describing how to connect to it via SMTP:&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/office/pop-imap-and-smtp-settings-for-outlook-com-d088b986-291d-42b8-9564-9c414e2aa040" target="_blank"&gt;https://support.microsoft.com/en-us/office/pop-imap-and-smtp-settings-for-outlook-com-d088b986-291d-42b8-9564-9c414e2aa040&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Enter the required credentials to your Splunk email settings, and it should work.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 21:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684285#M15928</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-15T21:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684481#M15929</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have put the smtp server name in my email settings in splunk...but the issue is a bit complex , all the previous alerts/reports are coming on time which are created on splunk but only the one created by me lately are not coming ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684481#M15929</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-17T10:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684560#M15930</link>
      <description>&lt;P&gt;So you have previous alerts which send email successfully, but when you make new alerts, they do not send email?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 20:27:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684560#M15930</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-17T20:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684599#M15931</link>
      <description>&lt;P&gt;Yes absolutely , the new alerts or reports that I am creating is unable to get notified through emails...If you have any suggestion kindly help&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 05:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684599#M15931</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-18T05:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684604#M15932</link>
      <description>&lt;P&gt;Also , i have the following error which is generated for only one previous alert , if you could please look and see what other steps I can take , if that helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-04-18 05:18:47,938 +0000 ERROR sendemail:187 - Sending email. subject="Splunk Alert: ITSEC_Backup_Change_Alert", encoded_subject="Splunk Alert: ITSEC_Backup_Change_Alert", results_link="*****", recipients="['it-security@durr.com']", server="********"&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 06:02:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684604#M15932</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-18T06:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684867#M15933</link>
      <description>&lt;P&gt;What happens if you manually use the sendemail command?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| sendemail to="it-security@durr.com" subject="Test mail" message="Test mail message"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 15:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684867#M15933</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-20T15:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684873#M15934</link>
      <description>&lt;P&gt;OK. Let me jump in with some organizational stuff.&lt;/P&gt;&lt;P&gt;1. The Answers forum is not a free support service. It's a platform for users to exchange knowledge and help each other. So it's very useful if the threads are appropriately named - it makes searching in the future way easier.&lt;/P&gt;&lt;P&gt;2. When you're creating a new thread and writing "I'm facing the same issue as you" what are you refering to? What issue? Who's facing? If you're refering to other issue reported elsewhere, post a link for reference.&lt;/P&gt;&lt;P&gt;3. Please provide as much info as you can to help people help you - for example, the information that your alerting used to work OK and suddenly stopped is a very important knowledge. You also posted the first - less important - line from the sendemail log - the next line should contain the actual error.&lt;/P&gt;&lt;P&gt;And more to the point - if something used to work and doesn't do that anymore, something must have changed. If you're absolutely sure (and double-checked it) that nothing changed on your side - something must have changed in the environment your Splunk is located in. Maybe the mail server's settings have changed, maybe your organization's firewall policies changed. Maybe you need to authenticate when sending outgoing email and the user/password you're using is&amp;nbsp; no longer valid. Have you verify if you have connectivity to your configured email server from your search head? Did you try to manually connect to the server and initiate SMTP transaction? Did you get any errors?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 18:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684873#M15934</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-20T18:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684914#M15935</link>
      <description>&lt;P&gt;I am getting the following error :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;command="sendemail", (*****SMTP; Client was not authenticated to send anonymous mail during MAIL FROM', '*****.com') while sending mail to: it-security@durr.com&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 19:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684914#M15935</guid>
      <dc:creator>shakti</dc:creator>
      <dc:date>2024-04-21T19:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684915#M15936</link>
      <description>&lt;P&gt;This is a message saying that the server you're trying to send your emails with doesn't let you do so (at least not without proper authentication first). It's something you have work with your email server provider (or configure proper settings on your Splunk server).&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 19:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/684915#M15936</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-21T19:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: alerts</title>
      <link>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/685017#M15937</link>
      <description>&lt;P&gt;This error would indicate an authentication problem. You should double-check your SMTP settings to ensure that they contain authentication settings for a valid account that can send email through your email provider.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 18:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Cannot-send-email-alerts/m-p/685017#M15937</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-22T18:40:08Z</dc:date>
    </item>
  </channel>
</rss>

