Alerting

Alert not Emailing

kholleran
Communicator

Hello,

I have an SMTP server that is unauthenticated. I have the server IP set up in Splunk Manager. I used this on a test splunk server within the same subnet (windows 2003 32 bit box) just fine.

However, my production box is not emailing (64 bit Win 2008 server - firewall opened for SMTP). I see the server connect to the mail server, then it disconnects without sending a message. My alert search criteria is returning results and should be emailing.

From mail Server:

07/28/2010 10:23:02 AM SMTP Server: SPLUNK_SERVER connected 07/28/2010 10:23:02 AM SMTP Server: SPLUNK_SERVER disconnected. 0 message[s] received

Is there anywhere else i can look? Is there a log file from Splunk that would clue me into what is happening when it is connecting to my mail server?

Thanks.

Kevin

Tags (1)
1 Solution

the_wolverine
Champion

Check the $SPLUNK_HOME/var/lib/splunk/python.log for errors related to email/smtp.

View solution in original post

kholleran
Communicator

Thanks! That had what I needed and found that the messages were being rejected as SPAM.... funny that the mail server log didn't say that....

Thanks again!

0 Karma

the_wolverine
Champion

Check the $SPLUNK_HOME/var/lib/splunk/python.log for errors related to email/smtp.

kholleran
Communicator

Note: the Splunk server and the mail server are on different subnets where as the test server that worked was on the same subnet. Not sure if that will make a difference.

Thanks for any help.

0 Karma
Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...