Splunk Enterprise Security

Email alert not triggering

maheshnc
Path Finder

Hello, we have a DMC configured on Splunk Licence Master, I need to enable all the critical resource utilization alerts on DMC and send email notifications. I have configured the server setting under settings>server setting>Email settings and set up the same configurations as on our search head (which is successfuly generating email notifications) but the thing is, alerts are triggering but but I am not receiving any email notifications. can somebody help me to figure out the root cause?

Note: Network connectivity established between mail server and LM server.

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@maheshnc - Search for internal logs to understand and troubleshoot the issue further.

index=_internal NOT source=*_access* "<title of the alert>"

 

And see what logs tell you.

 

I hope this helps!!! Kindly upvote!!!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Or specifically - if the alert _is_ being triggered but there is a problem with email delivery, search for anything regarding sendemail.py

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...