Hi,
We can't see alert notification via email by using "save as Alert" on the search that we want to trace.
i configured Settings > Server settings > Email Settings. i entered all inputs required. For example; Mail host link and port, User name, password.... But i still don't receive an email notification.
When i use sendemail, i get results emailed, but when I use a schedule for a triggered alert, I don't get an email notification.
How can i solve this issue ?
hi alican,
what operating system you use?
Of Course it's just temporary solution, but try re save email settings in Splunk.
Same issue here with 6.4.0. But sendemail didn't work as well.
Workaround worked fine.
Had the same problem on Splunk 6.3.2, after re-save the problem was solved.
Crazy!!! Also for me on Splunk 6.3.3, resaving the email settings solved the problem!!!
Hi @BBakkenes, @DimkoBilanko, and @alican,
Were any of you able to file a support case to report this issue?
Thanks!
Hey there!
I've come across a similar issue. Currently have mail notifications using gmail SMTP. Here's what I'm seeing in the splunkd.log:
11-18-2015 12:00:02.633 -0800 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://[omitted]/app/search/@go?sid=scheduler_YW5kcmV3LmhpbGw__search__RMD50d06411b8621c38a_at_1447876800_14745" "ssname=[omitted]" "graceful=True" "trigger_time=1447876801" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler_YW5kcmV3LmhpbGw__search__RMD50d06411b8621c38a_at_1447876800_14745/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: [omitted]@[omitted].com
To mitigate, I've reconfigured the mail settings on the instance. However, this has already happened twice. I'd like to get to the root of the issue.
Thanks,
Andrew,
Hi @alican, our engineers are asking if you can file a support ticket to help investigate the issue you're seeing a bit further. It's not fully clear from the logs whether this is a bug, a problem with your SMTP server, or maybe something wrong with the email configuration.
Here is a resource for working with support:
http://www.splunk.com/en_us/support-and-services/support-programs.html
Let me know if you have any further questions.
Thanks!
Hi @alican,
Thanks for your question. I am a technical writer here at Splunk and I would like to look into this for you. Let me run your question by our engineers and I'll let you know what I find out. Please stay tuned and feel free to post further questions or comments here.
Thanks!
hi,
We couldn't solve that case unfortunatly.
Also we can receive email information by using sendmail search but we can't receive email by using scheduler "save as Alert" and such.
This is important for us. If you can take a look in to this asap, it would be very nice
thank you very much
ERRORS LOGS
splunkd file
ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler__admin__search__RMD5131a0bf9ef43f8b3_at_1432..." "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432731301" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduler_adminsearchRMD5131a0bf9ef43f8b3_at_1432731300_269/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
[16:53:21]: 2015-05-27 16:00:13,399 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
2015-05-27 16:00:14,443 +0300 ERROR sendemail:115 - Sending email. subject="Splunk Alert: XXX_Top_IP_Alert", results_link="http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduleradminsearchRMD503b2a30f8d178922_at_1432731600_280%20%7C%20head%202%20%7C%20tail%201&earliest=0&latest=now", recipients="[u'alican.uzunhan@XXX.com']", server="XXX-smtp.com:587"
2015-05-27 16:00:14,443 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
2015-05-27 16:40:07,279 +0300 ERROR sendemail:115 - Sending email. subject="Splunk Alert: 500 ALERT 2", results_link="http://splunk.XXX.com:8000/app/search/@go?sid=scheduleradminsearch_RMD5131a0bf9ef43f8b3_at_1432734000_360", recipients="[u'alican.uzunhan@XXX.com']", server="XXX-smtp.com:587"
2015-05-27 16:40:07,279 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
phyton file
[16:58:28] 05-27-2015 14:20:07.420 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler__admin__search__RMD5131a0bf9ef43f8b3_at_1432..." "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432725606" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduler_adminsearchRMD5131a0bf9ef43f8b3_at_1432725600_92/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:00:13.528 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163%20%7C%20head%201%20%7C%20tail%201&earliest=0&latest=now" "ssname=XXX_Top_IP_Alert" "graceful=True" "trigger_time=1432728012" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163/per_result_alert/tmp_0.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:00:14.537 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163%20%7C%20head%202%20%7C%20tail%201&earliest=0&latest=now" "ssname=XXX_Top_IP_Alert" "graceful=True" "trigger_time=1432728012" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163/per_result_alert/tmp_1.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:25:02.208 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduleradminsearchRMD5131a0bf9ef43f8b3_at_1432729500_212" "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432729501" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD5131a0bf9ef43f8b3_at_1432729500_212/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:55:02.214 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduleradminsearchRMD5131a0bf9ef43f8b3_at_1432731300_269" "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432731301" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearch_RMD5131a0bf9ef43f8b3_at_1432731300_269/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com