Alerting

How to set up email alerts for Splunk running on a Docker

niddhi
Explorer

Hi,

I have Splunk instance running on a docker and the docker is running on an EC2-instance.
I am trying to configure email settings for sending the dashboard reports but it doesn't seem to work.
I don't have an explicit smtp server, therefore I was trying to use smtp.gmail.com:587, but its also not working.

Any pointers on how can I get the email alerts working.

I am very new to all this.
Please let me know if I am missing anything obvious here.

Thanks

0 Karma

brettw
Splunk Employee
Splunk Employee

You might be getting blocked by AWS security groups.  Try creating a security group allowing outbound to that address and port.  Don't forget to assign it to the instance where it is running.

Once that is in place, try making an outbound connection from the instance running docker (but not inside docker itself).

openssl s_client -connect smtp.gmail.com:587

If successful, you will see a connection and a certificate sent back.  Then, at least, you'll know you can connect from the instance itself.

0 Karma

sarvesh_11
Communicator

Hi @niddhi , were you able to do this?

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...