Hello all, we're configuring Splunk Enterprise security app within our environment, while testing alerts the alert actions for sending email notifications are not working.
Checked the internal error logs and observed the below. Any idea what is causing this error?
ERROR:root:(501, b'Syntax error, parameters in command "mail FROM:<internal server> size=9571" unrecognized or missing'
ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/search/bin/sendemail.py
@kkrises - I think you need to setup the email server configuration - https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification
I hope this helps!!!
Found the issue, thanks