Alerting

Splunk 6.6.0 (SMTP Requirement)

muhammadamir
New Member

Hello Support,
I have changed my local SMTP server, & it is running on a windows 2012 R2 server. I changed the settings of SMTP in splunk to point to the new windows based (SMTP), server but it is no longer sending me alerts, I need to make splunk send me alerts using our new SMTP server, Is there anything, Im missing? Please, someone reply ASAP, as it urgent! Also, how can I send a quick test alert, so I can check it is actually working from splunk?

Tags (1)
0 Karma

sudosplunk
Motivator

Hello muhammadamir,

It is hard to figure out the issue without looking at your settings. However, to test email alerts, you can use "sendmail" search command.

0 Karma

MuS
SplunkTrust
SplunkTrust

small correction here, the command is sendemail http://docs.splunk.com/Documentation/Splunk/6.6.0/SearchReference/Sendemail

And as usual check index=_internal sourcetype=splunkd for that host and see if you find any errors related to smtp.

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...