Hi,
Can you please how to to create a alert and send email using smtp server.
We have two seperate host s for indexer and search head.
Thanks,
You can do it in SPL, too, with | sendemail
:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Sendemail
Have a look at this answer I just made about alert_actions.conf. This might help:
I created a alert using in search head and scheduled by using cron job
under email settings gave hostaname and port number still am not receiving any emails am not seeing any logs in the python.log.
Sending email alerts via smtp is a feature splunk provides out of the box, there is no need to build it yourself.
See https://docs.splunk.com/Documentation/Splunk/7.2.3/Alert/Emailnotification for how to configure smtp servers into your splunk.
If you just want to learn how splunk does that, see sendemail.py in etc/apps/search/bin and the corresponding alert_actions.conf entry.