Spread our blog

How to Configure Email Alerting using Gmail SMTP in SPLUNK

Step1: Configure Email Settings In SPLUNK

Configuring SPLUNK to connect to the gmail servers is very simple.

In Splunk, navigate to: “Settings > Server Settings > Email  settings

1) There you have to configure “Mail Server Settings”.

Example :-  Mail host = smtp.gmail.com:587

Email security = Enable TLS

Username = SplunkGeek@gmail.com ( YOUR_GMAIL_ADDRESS)

Password = ******** ( YOUR_GMAIL_PASSWORD )

Confirm Password = ********

Screenshot1

2) Now configure the “Email Format”.

Screenshot2

3) Now click on save.

Screenshot3

Step2: Gmail account settings

1) At first you have to sign in into your gmail account through your credentials.

 

Screenshot9

 

2)Then you have to allow lesssecureapps option of your account.

Now you have to go the https://myaccount.google.com/lesssecureapps for allow the less secure apps. Now your gmail is fully configured to get the email alert from the SPLUNK server.

Screenshot10

 

Step3: Create an alert.

For creating an alert at first you have to write a query and save as an alert.

 

Screenshot4

 Step4: Configure the alert.

  1. Give the alert name and description.Here we configure this alert which will be generated in every two minutes.The query will show the data of last 24 hours output as a result.

Screenshot5

  1. Now you have to set the “Trigger Conditions” as per your requirement.

Here we have set the “Trigger Conditions” as Number of Results is greater than 0 . Also set the Trigger as Once.

Screenshot6

  1. Set the “Trigger Actions”

Click on  the “Add Actions” and select the “send email” option.

Screenshot7

  1. Now set the “send email”

Here you give your gmail address and also can set the Priority. You can include multiple options as per your requirement. Then click on save.

You can also know about :  Create a Marker Gauges in Splunk Table

Now whenever the condition will match ,alert will be generated and  the results will be forwarded to your gmail.

Screenshot8

Step5: Check the gmail account.

You can check your gmail account.There you will find the SPLUNK alert and also can see the results.

Screenshot11

 

Screenshot12

Hope this has helped you in achieving the below requirement without fail :

How to Configure Email Alerting using Gmail SMTP in SPLUNK

Happy Splunking !!

 

What’s your Reaction?
+1
+1
+1
1
+1
+1
+1
+1

Spread our blog
Previous articleUsage of Splunk EVAL Function : IF
Next articleUsage of Splunk commands : HEAD
Passionate content developer dedicated to producing result-oriented content, a specialist in technical and marketing niche writing!! Splunk Geek is a professional content writer with 6 years of experience and has been working for businesses of all types and sizes. It believes in offering insightful, educational, and valuable content and it's work reflects that.

5 COMMENTS

  1. Hi,

    I would like to know how we can index email attachment contents into Splunk ?

    For example : If I send a mail to you with an attachment, I would like to get the contents in the attachment indexed into splunk

    Thanks&Regards,
    Kiran

LEAVE A REPLY

Please enter your comment!
Please enter your name here