Using the query to send email to my ID which I have configured in email settings. If i trigger the Alert I'm getting the email but if using "sendemail to" command in search it's not sending the email and throwing below error.
Query:
index="_internal" | top 5 host | sendemail to="****@gmail.com"
Error:
command="sendemail", [Errno 10061] No connection could be made because the target machine actively refused it while sending mail
I think by default sendemail uses localhost as the mail server. Could be wrong there..
Anyway, we had similar issues with sendemail from the search string, and speciying the STMP host fixed it for us.
index="_internal" | top 5 host | sendemail to="whatever@gmail.com" server=yourmailserver.fqdn.name
https://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Sendemail