Deployment Architecture

Email Utility on UNIX Box for Splunk

rohitvjoshi
Path Finder

Hi Splunkers ,

We have tried to set Alert in Deployment manger to email address ,we have done all the set up in splunk related to Email setting i.e.-SMTP Server. we have done same configuration in Search Heads as well . We are getting alert email via Search Heads but not from Deployment Managers.We also checked the logs for related to triggerd alert , they having same configuration.

My Question is related to UNIX BOX , Do we need to install the EMAIL UTILITY in UNIX BOX where we have installed the Splunk OR do we require UNIX EMAIL utility to trigger mails apart from splunk email settings.

Thanks
Rohit

Tags (2)
0 Karma
1 Solution

burwell
SplunkTrust
SplunkTrust

Hello @rohitvjoshi Can you tell us what you mean by a deployment manager? If you mean deployment server and they have the alert_actions.conf pointing to SMTP server that the deployment server can talk to, this should work. I do that very thing.

View solution in original post

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello @rohitvjoshi Can you tell us what you mean by a deployment manager? If you mean deployment server and they have the alert_actions.conf pointing to SMTP server that the deployment server can talk to, this should work. I do that very thing.

0 Karma

rohitvjoshi
Path Finder

@Burwell --Its Deployment server only , I have added configuration under alert_actions.conf but it is not working while i have done same for Search Heads, it working perfect. My Question is related to UNIX BOX , do we need to add email utility in unix box ?

0 Karma

burwell
SplunkTrust
SplunkTrust

Splunk uses the standard email.

Can you try running sendemail on your deployment server per the example here https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchReference/Sendemail

It could be your mail server won't take mail from the deployment server.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...