Reporting

Error sending email

eholz1
Builder

Hello All,

I have splunk enterprise at 7.3.1 on Windows 2012 server.
I am trying to configure alerts to send email.
I have an smtp email server which requires no authenification.
Splunk thinks it sends email with an alert but then I get the error message below:

[Errno 10013] An attempt was made to access a socket in a way forbidden by its access permissions while sending mail

The windows firewall is off.
Has anyone else seen this error message? How to fix?

Thanks,
eholz1

0 Karma
1 Solution

eholz1
Builder

Hello Found the problem - McAfee Enterprise Ver. 8 was blocking the emails.
from a search on my error messages - From the StackOverflow web site:

McAfee was blocking it for me. I had to allow the program in the access protection rules
1.Open VirusScan
2.Right click on Access Protection and choose Properties
3.Click on "Anti-virus Standard Protection"
4.Select rule "Prevent mass mailing worms from sending mail" and click edit
5.Add the application to the Processes to exclude list and click OK

My fix was to in-check "Block" - I have a closed network so we are good.

eholz1

View solution in original post

0 Karma

eholz1
Builder

Hello Found the problem - McAfee Enterprise Ver. 8 was blocking the emails.
from a search on my error messages - From the StackOverflow web site:

McAfee was blocking it for me. I had to allow the program in the access protection rules
1.Open VirusScan
2.Right click on Access Protection and choose Properties
3.Click on "Anti-virus Standard Protection"
4.Select rule "Prevent mass mailing worms from sending mail" and click edit
5.Add the application to the Processes to exclude list and click OK

My fix was to in-check "Block" - I have a closed network so we are good.

eholz1

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...