Alerting

send email function does not seem to be working after upgrading to version 8.1.2

nls7010
Path Finder

We recently upgraded to version 8.1.2 Splunk and now our email alerts don't appear to be working.  I had this issue in version 6.6.3, but had not seen it since then (we did upgrade to 7.2.6 before moving to 8.1.2--did not see the issue then either).  I have looked at older logs that said to remove a few lines in the sendemail.py file and I found similar lines in the new sendemail and marked them out with a # sign, but it did not fix the issue.  We are delaying our upgrade of the Production system until we solve this email issue.  Any ass

Labels (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. Have you tried searching your _internal logs? What error is in the python log?

I did a search like

index=_internal host=myhead*  sourcetype=splunk_python

 

When I do the search I got something like

2021-04-30 23:07:02,181 +0000 INFO      sendemail:156 - Sending email. subject="My Alert", results_link="https://myhost.mydomain.com:8000/app/search/@go?sid=scheduler_YWRtaW5fc3BsdW5r__search__RMD54eadd0aa6872f5e8_at_1619824020_41", recipients="['me@mydoamin.com']", server="mymailserver.mydomain:25"
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...