Alerting

Unable to generate email alerts in splunk 6.0.1

balajsoz
Path Finder

Hi,
am using the splunk 6.0.1 60days enterprise trial version and have created a search called "IE-Alert" to trigger a alert whenever people opens up the Internet explorer in my local desktop.

And splunk also running in local desktop only.

Now i have updated the EMAIL ALERT SETTINGS under SETTINGS tab with Mail Host as proxy2.w1.com, username as "bjsoz" which is my username to log in my local office desktop and with the password.

I entered the same passwords also in this settings.

But still am not getting any email alerts even after i updated the setup of actions in alert genrations.

please help.

Also suggest how to setup the email setting for sending alert to my personal id which in gmail.com

Tags (2)
0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

How many real time searches are you running? How about how many cpu's are on that box?

0 Karma

yannK
Splunk Employee
Splunk Employee

check in the scheduler log to see if the alert triggered
$SPLUNK_HOME/var/log/splunk/scheduler.log

check the internal log for errors, the email script report in it.
$SPLUNK_HOME/var/log/splunk/python.log

A classic problem is that your mail server is refusing the connection, because of ip whitelist.

PS you can use splunk for that with index=_internal host=mysearchhead source=*/myfile.log

balajsoz
Path Finder

Hi yannk,

Thanks for the suggestion.
In scheduler.log, it showing the alerts perfectly.
And I have checked the python log and seen this below error and it comes continously whenevr alert trying to send email;
-> 2014-02-11 10:40:42,437 IST ERROR sendemail:357 - Sending email. subject="Splunk Alert: IE-ALERT-TEST;", results_link="http://localhost:8000/app/search/search?q=%7Cloadjob%20rt_scheduler__admin__search__RMD5fbb3cdb7aa7a...", recipients="['balaji.sozharajan@wipro.com']"
Please advice.

0 Karma

antlefebvre
Communicator

What is the backend mail server you are running? Are you the admin or is there another person responsible? I would suggest you ask if they can set up a service account to email from.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...