<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Step by Step to receive email alerts on Splunk in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38284#M768</link>
    <description>&lt;P&gt;This is how you send email from splunk and alert , what i need is receiving email on splunk and index the data received&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2013 14:02:57 GMT</pubDate>
    <dc:creator>royimad</dc:creator>
    <dc:date>2013-08-19T14:02:57Z</dc:date>
    <item>
      <title>Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38282#M766</link>
      <description>&lt;P&gt;How do i configure Splunk so i will be able to receive email alerts from other servers?&lt;BR /&gt;
Is there any step by step procedure that i should follow. I have Splunk on Linux machine and never did that before.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2013 09:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38282#M766</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-08-17T09:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38283#M767</link>
      <description>&lt;P&gt;If by 'another server' you mean a remote mailserver it's pretty easy.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Go to 'admin' and click 'system settings'&lt;/LI&gt;
&lt;LI&gt;Next click 'email alert settings'&lt;/LI&gt;
&lt;LI&gt;Set the appropriate values for your email host, username etc&lt;/LI&gt;
&lt;LI&gt;Set the link host so urls in the emails link back to the splunk alert correctly...ie..your splunk server host name&lt;/LI&gt;
&lt;LI&gt;Run a search &amp;amp; create an alert&lt;/LI&gt;
&lt;LI&gt;In the alert settings give it your email address&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You can also use the 'sendemail' command which you would append to the end of your saved search along with the server settings. This method is not so much an 'alert' though and you don't have access to the alert settings as far as I know.&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;P&gt;sourcetype=blah "keyword" | sendmail to="&lt;A href="mailto:youremail@"&gt;youremail@&lt;/A&gt;..." server="192.168.." etc. etc.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2013 21:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38283#M767</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-08-17T21:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38284#M768</link>
      <description>&lt;P&gt;This is how you send email from splunk and alert , what i need is receiving email on splunk and index the data received&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38284#M768</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-08-19T14:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38285#M769</link>
      <description>&lt;P&gt;Still doesn't know how to receive email on splunk ?! Anyidea or steps&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38285#M769</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-08-19T14:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38286#M770</link>
      <description>&lt;P&gt;Still doesn't know how to receive email on splunk ?! Anyidea or steps&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38286#M770</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-08-19T14:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38287#M771</link>
      <description>&lt;P&gt;ahh my bad. I read too quickly.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38287#M771</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-08-19T14:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38288#M772</link>
      <description>&lt;P&gt;A while ago I did something similar but not related to Splunk. But the idea is the same. &lt;/P&gt;

&lt;P&gt;A script is scheduled to run on the interval of your choice via chron. It retrieves e-mails and saves them out as a text file or whatever. I used PERL and the IMAP client MUTT. (&lt;A href="http://www.mutt.org"&gt;http://www.mutt.org&lt;/A&gt;)&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;install command line email client (Mutt)&lt;/LI&gt;
&lt;LI&gt;write a script (perl,python,bash etc.) that connects, retrieves messages and saves them out as a text file locally to a folder that Splunk has access to.&lt;/LI&gt;
&lt;LI&gt;In splunk create input that watches that folder&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;-j&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:17:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38288#M772</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-08-19T14:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38289#M773</link>
      <description>&lt;P&gt;I have used &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;IMAP App&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;to receive email on Splunk and connect to exchange server.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 07:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38289#M773</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-08-21T07:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Step by Step to receive email alerts on Splunk</title>
      <link>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38290#M774</link>
      <description>&lt;P&gt;for this purpose we have IMAP app. &lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 06:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Step-by-Step-to-receive-email-alerts-on-Splunk/m-p/38290#M774</guid>
      <dc:creator>saurabh_tek</dc:creator>
      <dc:date>2016-09-29T06:02:21Z</dc:date>
    </item>
  </channel>
</rss>

