Deployment Architecture

Email Utility on UNIX Box for Splunk

rohitvjoshi
Path Finder

Hi Splunkers ,

We have tried to set Alert in Deployment manger to email address ,we have done all the set up in splunk related to Email setting i.e.-SMTP Server. we have done same configuration in Search Heads as well . We are getting alert email via Search Heads but not from Deployment Managers.We also checked the logs for related to triggerd alert , they having same configuration.

My Question is related to UNIX BOX , Do we need to install the EMAIL UTILITY in UNIX BOX where we have installed the Splunk OR do we require UNIX EMAIL utility to trigger mails apart from splunk email settings.

Thanks
Rohit

Tags (2)
0 Karma
1 Solution

burwell
SplunkTrust
SplunkTrust

Hello @rohitvjoshi Can you tell us what you mean by a deployment manager? If you mean deployment server and they have the alert_actions.conf pointing to SMTP server that the deployment server can talk to, this should work. I do that very thing.

View solution in original post

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello @rohitvjoshi Can you tell us what you mean by a deployment manager? If you mean deployment server and they have the alert_actions.conf pointing to SMTP server that the deployment server can talk to, this should work. I do that very thing.

0 Karma

rohitvjoshi
Path Finder

@Burwell --Its Deployment server only , I have added configuration under alert_actions.conf but it is not working while i have done same for Search Heads, it working perfect. My Question is related to UNIX BOX , do we need to add email utility in unix box ?

0 Karma

burwell
SplunkTrust
SplunkTrust

Splunk uses the standard email.

Can you try running sendemail on your deployment server per the example here https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchReference/Sendemail

It could be your mail server won't take mail from the deployment server.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...