Check
cat /var/log/maillog
Check if any connection is refused by SMTP Server... If yes, then inform your IT Team
Try to check under Server Settings and Then Email Settings
Afterwards check Alert Action on Splunk UI
Maillog doesn't exist on Insights for infrastructure and our python.log file is empty.
SMTP server settings are set the same way as many other systems, but the alerts from splunk do not get sent.
Need a way to troubleshoot the issues.
Thanks,
Check in $SPLUNK_HOME/var/log/splunk/python.log
or use the search :
index=_internal source=*python.log*
I created an alert called "AllSplunkEnterpriseLevel - Email Sending Failures", if you needed an example it's available in github here or the app with all the alerts is available here, Alerts For Splunk Admins
Thank you.
You should click Accept
on this answer, @adoshi, to close the question.
@woodcock it might be worth noting this is a 2012 post and the user was last seen in 2015...