Deployment Architecture

Why could I not receive the alert email ?

rickyhsu7
Explorer

Hi All,

I use Splunk Enterprise.
I have set email setting like host through smtp.gmail.com:465
Besides, I can send email by command sendemail to.

However, the alert could not send email.
I checked the python.log, and it records server="localhost".
In my opinion, that's the key causing the problem.
So, could I avoid this problem?
I don't understand why it would change the server after I have set in email setting.
Please help me. Thank you.

0 Karma

rickyhsu7
Explorer

Yes, I have server=localhost in my alert_actions.conf. Should I modify it?

0 Karma

teunlaan
Contributor

You probably have an alert_actions.conf on your system that has server=localhost in it.
Please run a btool to check if this is the case.

If you also have Enterpise Security installed, make sure you import the app the had the alert_actions.conf file

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...