Alerting

Why is an email not being sent when my alert is triggered?

nitesh218
Engager

Hi

I created an alert that is triggered correctly, but the email is not sent by Splunk log i got error

[Errno 10060] A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond while sending mail to: user2@gmail.com

or sometimes

 [Errno 11004] getaddrinfo failed while sending mail to:user2@gmail.com 

My email settings in Server settings » Email settings

alert_action.conf

[email]
auth_password = password*****i
auth_username = user@gmail.com
mailserver = smtp.gmail.com:587
format = html
use_tls = 0      I changed this to 1 also, but email still wasn't sent
use_ssl = 0

My alert configuration is:
savedsearches.conf file

[request]
action.email = 1
action.email.priority = 2
action.email.reportServerEnabled = 0
action.email.to = user2@gmail.com
action.email.useNSSubject = 1
alert.severity = 4
alert.suppress = 1
alert.suppress.period = 30s
alert.track = 1
counttype = number of events
cron_schedule = */2 * * * *
description = resuest resive
dispatch.latest_time = now
display.events.fields = ["host","source","sourcetype","Msg"]
display.general.type = statistics
display.page.search.mode = verbose
display.page.search.tab = statistics
enableSched = 1
quantity = 1
relation = greater than
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = index="newpwm" source="SOCK_20150327_192217.log" Msg=Q*| eval vv=substr(Msg, 7,8) | Table _time Msg vv

Please help me. For 1 day I've tried many times to use my company domain and port, but it's not working. I want an email sent only when the alert is triggered.

0 Karma
1 Solution

NOUMSSI
Builder

Hi,
if your splunk instance is installed locally, it can't send emails because emails are going from one server to anothers.
In spite you are connected to internet when you work on your local splunk instance, you are not on a server. So your splunk instance couldn't send email.
But if your splunk instance is on the cloud, it'll send emails correctly.

View solution in original post

NOUMSSI
Builder

Hi,
if your splunk instance is installed locally, it can't send emails because emails are going from one server to anothers.
In spite you are connected to internet when you work on your local splunk instance, you are not on a server. So your splunk instance couldn't send email.
But if your splunk instance is on the cloud, it'll send emails correctly.

nitesh218ss
Communicator

thanks for reply sir

0 Karma

nitesh218ss
Communicator

my company give new mailid is which authorize for sending mail so i use this they sent mail now

0 Karma

ppablo
Retired

Hi @nitesh218ss

If your problem is solved, don't forget to accept @NOUMSSI's answer by clicking on "Accept" below their answer.

0 Karma

stephanefotso
Motivator

Is your splunk instance is installed in the cloud? or locally?
If locally, check the external exchange server that you use to send emails.

SGF
0 Karma

nitesh218
Engager

where i get this external exchange server sir and how i change this
please help me

0 Karma

stephanefotso
Motivator

No, just to say you need to host your splunk instance before, Since you must be in the cloud to access to mail servers, which allow the email sending.

SGF
0 Karma

nitesh218
Engager

localhost:8000

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...