Archive

Why could I not receive the alert email ?

Explorer

Hi All,

I use Splunk Enterprise.
I have set email setting like host through smtp.gmail.com:465
Besides, I can send email by command sendemail to.

However, the alert could not send email.
I checked the python.log, and it records server="localhost".
In my opinion, that's the key causing the problem.
So, could I avoid this problem?
I don't understand why it would change the server after I have set in email setting.
Please help me. Thank you.

0 Karma

Explorer

Yes, I have server=localhost in my alert_actions.conf. Should I modify it?

0 Karma

Contributor

You probably have an alert_actions.conf on your system that has server=localhost in it.
Please run a btool to check if this is the case.

If you also have Enterpise Security installed, make sure you import the app the had the alert_actions.conf file

0 Karma