Alerting

How to troubleshoot why Splunk unable to send alert emails to the mail server?

jishelar
Explorer

Hi,

Splunk is not able to send alert/mail. We are getting below error message.

08-02-2016 04:49:05.799 -0500 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https:10.126.33.22@go?sid=scheduler_cms_Q0NNUy1UQS1vbnByZW0tcGxhdGZvcm0tcmVwb3J0aW5nRMD5e748673ac079e532_at_1470131340_24_577E0027-6C88-4096-88B0-9AF1F73327F8" "ssname=Splunk_D_SLM_IR_SHR" "graceful=True" "trigger_time=1470131342" results_file="/opt/splunk/var/run/splunk/dispatch/schedulercms_Q0NNUy1UQS1vbnByZW0tcGxhdGZvcm0tcmVwb3J0aW5n_RMD5e748673ac079e532_at_1470131340_24_577E0027-6C88-4096-88B0-9AF1F73327F8/results.csv.gz"': ERROR:root:Connection unexpectedly closed while sending mail to: splunk@localhost.localdomain

Can somebody please help here?

Thanks,
Jitendra

0 Karma

JDukeSplunk
Builder

Try sending a message via telnet to yourself from the splunk server. If the server can do it via telnet, the problem is somewhere in Splunk/Python. If you cannot send via the command prompt, then the issue could be on the mail server.

http://www.yuki-onna.co.uk/email/smtp.html

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...