Reporting

How to determine a sendmail issue?

tkwaller_2
Communicator

I am getting an error after settign up email alerting
The error I get is:

08-29-2018 15:33:19.626 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://ourdomain.com/app/ourapp/@go?sid=scheduler__twaller__ourapp__ABC5980879bd671d6025_at_1535556780_96501" "ssname=Todds Test Email" "graceful=True" "trigger_time=1535556798" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__twaller__ourapp__ABC5980879bd671d6025_at_1535556780_96501/results.csv.gz"':  ERROR:root:Connection unexpectedly closed while sending mail to: me@gmail.com
My email settings are:

Mail Server Settings
Mail host
smtp-relay.gmail.com:465

Email security =Enable SSL

No username/pass

Link hostname
https://ourdomain.com

Send emails as
MyCompany
Any ideas why I might be getting these errors about the closing connection? I get the same when searching and using sendemail

like:

index=main | head 5 | sendemail to=me@gmail.com server=smtp-relay.gmail.com:465 subject="Here is an email notification" message="This is an example message" sendresults=true inline=true format=raw sendpdf=true

I appreciate the assistance as always

0 Karma
1 Solution

tkwaller_2
Communicator

Found the issue. Well issues:

  1. If the search takes to long the sendemail will fail with this error

  2. The "Send emails as" field in the request sent to the relay server requires domain name to be within my domain. For example
    if my domain is google.com it will only allow emails from senders ending in @google.com

Changed from noreply-splunkdev
to noreply-splunkdev@gmail.com

View solution in original post

0 Karma

tkwaller_2
Communicator

Found the issue. Well issues:

  1. If the search takes to long the sendemail will fail with this error

  2. The "Send emails as" field in the request sent to the relay server requires domain name to be within my domain. For example
    if my domain is google.com it will only allow emails from senders ending in @google.com

Changed from noreply-splunkdev
to noreply-splunkdev@gmail.com

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...