Alerting

Why am I not receiving alert by mail even though I've configured correctly?

hichem_khalfi
Path Finder

helllo

 

I can't receive an email alert despite having configured it correctly
the alert is launched on the portal indicating the outcome but the email is absent

1- mail serer configuration!
smptm.gmail.com: 587
I added a gmail address with password

2-alert configuration:
I put a destination address: I put an outlook address

 

please help me to fix it

Labels (1)
Tags (1)
0 Karma

hichem_khalfi
Path Finder

hi @richgalloway 

1- i'm using smtp.gmail.com:587     is correct or no ???? 

2- what command should i use to verify sending mail ??? sorry i d'ont know it ,  just i write  index=_internal ???

0 Karma

richgalloway
SplunkTrust
SplunkTrust

1. That setting looks better.

2. It's a simple search for "sendemail" in the _internal index.

index=_internal "sendemail"
---
If this reply helps you, Karma would be appreciated.

hichem_khalfi
Path Finder

Hi @richgalloway 

Bad username and password 

it's a password problem but I have a problem:

my password is made up of 9 syllables

example: 123456789

 

on the other hand I notice that the registered password is composed of only 6 syllables because there are 6 stars (******), I tried to delete all the registered passwords but always the same problem

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

First, verify the email setup is truly correct.  "smptvm.gmail.com: 587" looks incorrect to me.

Next, check index=_internal for "sendemail" messages.  These will verify the messages were handed off to the SMTP server or give an error explaining why they couldn't be handed off.

Finally, if the messages were successfully delivered to the SMTP server, contact your email admin to determine what your mail server(s) did with it.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...