<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Saved Searches not emailing out in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14738#M1633</link>
    <description>&lt;P&gt;I cannot get to that website you posted and also in the saved search box i dont have a field for "From" or "Sender"  But i must say that my saved searches have worked for 1yr then all of a sudden stopped with that error i put in the original post.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2010 22:08:57 GMT</pubDate>
    <dc:creator>jtwcarboy</dc:creator>
    <dc:date>2010-06-09T22:08:57Z</dc:date>
    <item>
      <title>Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14733#M1628</link>
      <description>&lt;P&gt;I have saved searches and all of a sudden with no changes they are returning this error to the python.log file.&lt;/P&gt;

&lt;P&gt;ERROR Error in 'sendemail': (128, 'Network is unreachable') while sending mail to: user@user.com&lt;/P&gt;

&lt;P&gt;I checked manually and i can send an email from this server to myself just splunk isnt able to send emails and im not sure how to resolve this issue.
I can telnet over 25 to my mailhost so this has to be something simple to do with splunk itself.&lt;/P&gt;

&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2010 01:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14733#M1628</guid>
      <dc:creator>jtwcarboy</dc:creator>
      <dc:date>2010-06-03T01:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14734#M1629</link>
      <description>&lt;P&gt;Have you tried running the &lt;CODE&gt;sendemail&lt;/CODE&gt; command manually?  I'm guessing that you are using the scheduled saved searched with email alerting?  If you are running on a unix OS with a local MTA, then you may want to forward your email to localhost and let your local MTA handle there rest (this will give you a small buffer if you do experience a temporary network outage)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2010 04:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14734#M1629</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-06-03T04:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14735#M1630</link>
      <description>&lt;P&gt;What host is set in &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/alert_actions.conf&lt;/CODE&gt; in the &lt;CODE&gt;[email]&lt;/CODE&gt; stanza.  The host is set with &lt;CODE&gt;hostname=&amp;lt;hostname&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2010 04:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14735#M1630</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-06-03T04:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14736#M1631</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Have you done the right settings at this page?
&lt;A href="http://lxs-monet:8000/en-US/manager/unix/configs/conf-alert_actions/email/?action=edit" rel="nofollow"&gt;http://lxs-monet:8000/en-US/manager/unix/configs/conf-alert_actions/email/?action=edit&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Make sure that you entered an VALID sender-email adress. With valid, I mean: [somename]@[somedomain].com
Somename doesn't have to be a valid name (at my configuration)
Mine email function did not work until I changed the sender-adress.. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2010 14:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14736#M1631</guid>
      <dc:creator>deletethisaccou</dc:creator>
      <dc:date>2010-06-04T14:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14737#M1632</link>
      <description>&lt;P&gt;There is no alert_actions.conf file as im not using alerts but im only running saved searches every morning but not alerts.  &lt;/P&gt;

&lt;P&gt;Also what is the usage for the sendemail.py command as when i run it it get this:&lt;/P&gt;

&lt;P&gt;import: Unable to connect to X server ().&lt;BR /&gt;
import: Unable to connect to X server ().&lt;BR /&gt;
/opt/splunk/etc/searchscripts/sendemail.py[4]: from:  not found&lt;BR /&gt;
import: Unable to connect to X server ().&lt;BR /&gt;
/opt/splunk/etc/searchscripts/sendemail.py[8]: importanceMap:  not found&lt;BR /&gt;
/opt/splunk/etc/searchscripts/sendemail.py[9]: highest::  not found&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2010 22:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14737#M1632</guid>
      <dc:creator>jtwcarboy</dc:creator>
      <dc:date>2010-06-09T22:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14738#M1633</link>
      <description>&lt;P&gt;I cannot get to that website you posted and also in the saved search box i dont have a field for "From" or "Sender"  But i must say that my saved searches have worked for 1yr then all of a sudden stopped with that error i put in the original post.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2010 22:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14738#M1633</guid>
      <dc:creator>jtwcarboy</dc:creator>
      <dc:date>2010-06-09T22:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14739#M1634</link>
      <description>&lt;P&gt;In splunk terminology, searches that are scheduled and send emails, are alerts.  The email sender is saying it cannot access your mail server.  The alert_actions config screen is where you say how for it to reach your mailserver.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 23:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14739#M1634</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-07-02T23:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches not emailing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14740#M1635</link>
      <description>&lt;P&gt;If you never configured alert_actions, sendemail would try to connect to localhost, port 25, to send the email.  It's possible something about your netwrorking configuration or environment has changed.  It seems quite likely though that configuring the alert_actions as in the above url (but using your splunk server) will resolve the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-Searches-not-emailing-out/m-p/14740#M1635</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2020-09-28T09:14:34Z</dc:date>
    </item>
  </channel>
</rss>

