Alerting

Can I send alert emails if my Splunk instance is in a VM?

jenniferleenyc
Engager

I'm trying to schedule an alert system that notifies individuals on a daily basis based on a trigger. However, I haven't received any emails from my Splunk instance which is in a VM and I don't know how to debug it. My search query is: `

host=jenniferleeVM | 'IS_EXPIRED' | where expirationStatus="expired" `
where IS_EXPIRED is a macro that creates a field, expirationStatus with "expired" and "active" as potential outcomes. The host is set to localhost.

Is there a way to fix this? Or can Splunk instances installed in a VM not email alert notifications?

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You can send email alerts from a VM. You will need to configure your outbound SMTP server properly thought.

Read Here : http://docs.splunk.com/Documentation/Splunk/6.4.2/Alert/Emailnotification#Configure_email_notificati...

jenniferleenyc
Engager

How do I configure the outbound SMTP server through the email configuration settings? I used this site (http://blogs.splunk.com/2014/01/31/testing-alerts-using-local-smtp-server/) to test my alert notification system but it didn't work.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...