I am trying to get alerting to send emails from our Windows 2008 (4.1.6 splunk) server. The email server is an open relay, yet splunk does not send the email. I believe the problem is with Windows not having an email client or forwarder.
Can someone provide some guidance on this? If I need a client, what is the recommendation?
Yes. It needs to be an SMTP service (we're using Lotus Domino) and it needs to be in the "mail host" field. I would recommend that you configure the SMTP box to require authentication or have some restrictive sending rules in place to prevent it from being abused.
If you need it, I can post shots of my Splunk settings for you
You will need an email client (I.e. A server that sends out emails)
In Manager » System settings » Email alert settings, you will need to specify the host address of this email client to send out email alerts on behalf of your Splunk instance.