<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert not Emailing in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21844#M160</link>
    <description>&lt;P&gt;Thanks!  That had what I needed and found that the messages were being rejected as SPAM....  funny that the mail server log didn't say that....  &lt;/P&gt;

&lt;P&gt;Thanks again!&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jul 2010 00:14:25 GMT</pubDate>
    <dc:creator>kholleran</dc:creator>
    <dc:date>2010-07-29T00:14:25Z</dc:date>
    <item>
      <title>Alert not Emailing</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21841#M157</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have an SMTP server that is unauthenticated. I have the server IP set up in Splunk Manager. I used this on a test splunk server within the same subnet (windows 2003 32 bit box) just fine.&lt;/P&gt;

&lt;P&gt;However, my production box is not emailing (64 bit Win 2008 server - firewall opened for SMTP). I see the server connect to the mail server, then it disconnects without sending a message. My alert search criteria is returning results and should be emailing.&lt;/P&gt;

&lt;P&gt;From mail Server:&lt;/P&gt;

&lt;P&gt;07/28/2010 10:23:02 AM  SMTP Server: SPLUNK_SERVER connected
07/28/2010 10:23:02 AM  SMTP Server: SPLUNK_SERVER disconnected. 0 message[s] received&lt;/P&gt;

&lt;P&gt;Is there anywhere else i can look? Is there a log file from Splunk that would clue me into what is happening when it is connecting to my mail server?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 21:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21841#M157</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-07-28T21:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not Emailing</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21842#M158</link>
      <description>&lt;P&gt;Note: the Splunk server and the mail server are on different subnets where as the test server that worked was on the same subnet.  Not sure if that will make a difference.&lt;/P&gt;

&lt;P&gt;Thanks for any help.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 21:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21842#M158</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-07-28T21:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not Emailing</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21843#M159</link>
      <description>&lt;P&gt;Check the $SPLUNK_HOME/var/lib/splunk/python.log for errors related to email/smtp.  &lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 23:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21843#M159</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-07-28T23:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alert not Emailing</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21844#M160</link>
      <description>&lt;P&gt;Thanks!  That had what I needed and found that the messages were being rejected as SPAM....  funny that the mail server log didn't say that....  &lt;/P&gt;

&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2010 00:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-not-Emailing/m-p/21844#M160</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-07-29T00:14:25Z</dc:date>
    </item>
  </channel>
</rss>

