Alerting

Splunk alert is triggered but not sending the email

mufthmu
Path Finder

I set up a new splunk instance on my local machine, created a dummy alert but it did not send me any notification email even though it was triggered.
any idea what might cause this issue in the alert_actions.conf file?
thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mufthmu,
at first check if your Splunk Search Head reach the SMTP server on port you enabled (e.g. 465) using telnet from SH (telnet IP_SMTP_Server 465).
Then did you configured SMTP Server (as @arjunpkishore5 said) in [Setting -- Server Settings -- eMail Settings]?

If the above checks are Ok, check the dimension of your message and attachment, if one of them exceeds the eMail limits, it will be blocked.

Ciao.
Giuseppe

0 Karma

Praz_123
Path Finder

@gcusello 

Same issue am facing as i had checked above solution worked on that it is working fine ,Till September  received(email notification ) the report for the alert triggered but it is stopped from October. 

what could be the issue ??

Tags (2)
0 Karma

arjunpkishore5
Motivator

Have you setup the SMTP server settings ?

Check the mailserver section in alert_actions.conf - https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Alertactionsconf

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...