Splunk Enterprise Security

Email alert not triggering

maheshnc
Path Finder

Hello, we have a DMC configured on Splunk Licence Master, I need to enable all the critical resource utilization alerts on DMC and send email notifications. I have configured the server setting under settings>server setting>Email settings and set up the same configurations as on our search head (which is successfuly generating email notifications) but the thing is, alerts are triggering but but I am not receiving any email notifications. can somebody help me to figure out the root cause?

Note: Network connectivity established between mail server and LM server.

Labels (1)
0 Karma

SK99
Loves-to-Learn

@maheshnc , you might need to enable email relay from your DMC/LM server to Email server in order to send internal emails (as per your organizational policies.)

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't think you can "enable forwarding" on outlook com. You need to properly authenticate.

0 Karma

SK99
Loves-to-Learn

Yes, with email relay there is option for "IP address authentication"; means to authorize a specific server's IP address to send email through the relay service.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Interesting. Didn't expect that. But be aware that since you're most probably not using static public IPs on your Splunk components you'd be opening relaying from whatever is NAT-ed to the same IP.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@maheshnc - Search for internal logs to understand and troubleshoot the issue further.

index=_internal NOT source=*_access* "<title of the alert>"

 

And see what logs tell you.

 

I hope this helps!!! Kindly upvote!!!

0 Karma

maheshnc
Path Finder

maheshnc_0-1763380670341.png

Getting this error, not sure why

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... this is something that should be troubleshot with your email admins because there is apparently something wrong with your Splunk trying to authenticate to the email server.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Or specifically - if the alert _is_ being triggered but there is a problem with email delivery, search for anything regarding sendemail.py

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...