Alerting

Why am I not receiving email notifications after setting up an alert?

alican
Engager

Hi,

We can't see alert notification via email by using "save as Alert" on the search that we want to trace.

i configured Settings > Server settings > Email Settings. i entered all inputs required. For example; Mail host link and port, User name, password.... But i still don't receive an email notification.

When i use sendemail, i get results emailed, but when I use a schedule for a triggered alert, I don't get an email notification.

How can i solve this issue ?

Tags (2)

gyslainlatsa
Motivator

hi alican,

what operating system you use?

0 Karma

DimkoBilanko
Explorer

Of Course it's just temporary solution, but try re save email settings in Splunk.

vostro
Engager

Same issue here with 6.4.0. But sendemail didn't work as well.

Workaround worked fine.

0 Karma

BBakkenes
Explorer

Had the same problem on Splunk 6.3.2, after re-save the problem was solved.

0 Karma

marcoscala
Builder

Crazy!!! Also for me on Splunk 6.3.3, resaving the email settings solved the problem!!!

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hi @BBakkenes, @DimkoBilanko, and @alican,
Were any of you able to file a support case to report this issue?

Thanks!

0 Karma

andrewjhill
Path Finder

Hey there!

I've come across a similar issue. Currently have mail notifications using gmail SMTP. Here's what I'm seeing in the splunkd.log:

11-18-2015 12:00:02.633 -0800 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://[omitted]/app/search/@go?sid=scheduler_YW5kcmV3LmhpbGw__search__RMD50d06411b8621c38a_at_1447876800_14745" "ssname=[omitted]" "graceful=True" "trigger_time=1447876801" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler_YW5kcmV3LmhpbGw__search__RMD50d06411b8621c38a_at_1447876800_14745/results.csv.gz"':  ERROR:root:object of type 'NoneType' has no len() while sending mail to: [omitted]@[omitted].com

To mitigate, I've reconfigured the mail settings on the instance. However, this has already happened twice. I'd like to get to the root of the issue.

Thanks,

Andrew,

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hi @alican, our engineers are asking if you can file a support ticket to help investigate the issue you're seeing a bit further. It's not fully clear from the logs whether this is a bug, a problem with your SMTP server, or maybe something wrong with the email configuration.
Here is a resource for working with support:
http://www.splunk.com/en_us/support-and-services/support-programs.html

Let me know if you have any further questions.
Thanks!

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hi @alican,
Thanks for your question. I am a technical writer here at Splunk and I would like to look into this for you. Let me run your question by our engineers and I'll let you know what I find out. Please stay tuned and feel free to post further questions or comments here.
Thanks!

0 Karma

alican
Engager

hi,

We couldn't solve that case unfortunatly.
Also we can receive email information by using sendmail search but we can't receive email by using scheduler "save as Alert" and such.

This is important for us. If you can take a look in to this asap, it would be very nice

thank you very much

ERRORS LOGS

splunkd file

ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler__admin__search__RMD5131a0bf9ef43f8b3_at_1432..." "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432731301" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduler_adminsearchRMD5131a0bf9ef43f8b3_at_1432731300_269/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
[16:53:21]: 2015-05-27 16:00:13,399 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
2015-05-27 16:00:14,443 +0300 ERROR sendemail:115 - Sending email. subject="Splunk Alert: XXX_Top_IP_Alert", results_link="http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduler
adminsearchRMD503b2a30f8d178922_at_1432731600_280%20%7C%20head%202%20%7C%20tail%201&earliest=0&latest=now", recipients="[u'alican.uzunhan@XXX.com']", server="XXX-smtp.com:587"
2015-05-27 16:00:14,443 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
2015-05-27 16:40:07,279 +0300 ERROR sendemail:115 - Sending email. subject="Splunk Alert: 500 ALERT 2", results_link="http://splunk.XXX.com:8000/app/search/@go?sid=scheduler
adminsearch_RMD5131a0bf9ef43f8b3_at_1432734000_360", recipients="[u'alican.uzunhan@XXX.com']", server="XXX-smtp.com:587"
2015-05-27 16:40:07,279 +0300 ERROR sendemail:351 - object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com

phyton file

[16:58:28] 05-27-2015 14:20:07.420 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler__admin__search__RMD5131a0bf9ef43f8b3_at_1432..." "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432725606" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduler_adminsearchRMD5131a0bf9ef43f8b3_at_1432725600_92/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:00:13.528 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduler
adminsearchRMD503b2a30f8d178922_at_1432728000_163%20%7C%20head%201%20%7C%20tail%201&earliest=0&latest=now" "ssname=XXX_Top_IP_Alert" "graceful=True" "trigger_time=1432728012" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163/per_result_alert/tmp_0.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:00:14.537 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/search?q=%7Cloadjob%20scheduler
adminsearchRMD503b2a30f8d178922_at_1432728000_163%20%7C%20head%202%20%7C%20tail%201&earliest=0&latest=now" "ssname=XXX_Top_IP_Alert" "graceful=True" "trigger_time=1432728012" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD503b2a30f8d178922_at_1432728000_163/per_result_alert/tmp_1.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:25:02.208 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler
adminsearchRMD5131a0bf9ef43f8b3_at_1432729500_212" "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432729501" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearchRMD5131a0bf9ef43f8b3_at_1432729500_212/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com
05-27-2015 15:55:02.214 +0300 ERROR ScriptRunner - stderr from '/home/ubuntu/splunk/bin/python /home/ubuntu/splunk/etc/apps/search/bin/sendemail.py "results_link=http://splunk.XXX.com:8000/app/search/@go?sid=scheduler
adminsearchRMD5131a0bf9ef43f8b3_at_1432731300_269" "ssname=500 ALERT 2" "graceful=True" "trigger_time=1432731301" results_file="/home/ubuntu/splunk/var/run/splunk/dispatch/scheduleradminsearch_RMD5131a0bf9ef43f8b3_at_1432731300_269/results.csv.gz"': ERROR:root:object of type 'NoneType' has no len() while sending mail to: alican.uzunhan@XXX.com

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...