Alerting

How to set up email alerts for Splunk running on a Docker

niddhi
Explorer

Hi,

I have Splunk instance running on a docker and the docker is running on an EC2-instance.
I am trying to configure email settings for sending the dashboard reports but it doesn't seem to work.
I don't have an explicit smtp server, therefore I was trying to use smtp.gmail.com:587, but its also not working.

Any pointers on how can I get the email alerts working.

I am very new to all this.
Please let me know if I am missing anything obvious here.

Thanks

0 Karma

brettw
Splunk Employee
Splunk Employee

You might be getting blocked by AWS security groups.  Try creating a security group allowing outbound to that address and port.  Don't forget to assign it to the instance where it is running.

Once that is in place, try making an outbound connection from the instance running docker (but not inside docker itself).

openssl s_client -connect smtp.gmail.com:587

If successful, you will see a connection and a certificate sent back.  Then, at least, you'll know you can connect from the instance itself.

0 Karma

sarvesh_11
Communicator

Hi @niddhi , were you able to do this?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...