IBM Security QRadar SOAR

 View Only

Resilient V51 (Redhat 8) and fn_outbound_email

  • 1.  Resilient V51 (Redhat 8) and fn_outbound_email

    Posted Sat February 17, 2024 03:28 PM

    Hi,

    We migrated our soar to v51 (fresh install). We are using integration server. The self test is success:

    Successfully connected via STOMP!
    
    ------------------------
    ------------------------
    
    Running selftest for: 'fn-outbound-email'
    
    ------------------------
    
    fn-outbound-email:
    
    Unable to confirm public certificate has trust for 'emailProtection'. Continuing.
    
        selftest: success
    
        selftest output:
    
        {'state': 'success', 'reason': 'Send test email Successful'}
    
        Elapsed time: 0.020000 seconds
    
    ------------------------
    
    Successfully ran App's selftest!
    
    ------------------------
    
    ------------------------
    
    selftest complete

    Function always is running and send mail is not successful.

    The /var/log/maillog output is:

    Outfound mail playbook running fine but from /var/log/maillog:
    
    Feb 17 16:47:01 integration_server_host_name postfix/smtp[123782]: 2D7A382684D7: to=<ccc@ccc>, relay=[]:25, delay=4788, delays=4788/0.04/0.08/0.01, dsn=4.1.8, status=deferred (host [] said: 450 4.1.8 <integration_server_user@integration_server_host_name>: Sender address rejected: Domain not found (in reply to RCPT TO command))
    
    function trying to send mail from "integration_server_user@integration_server_host_name" and rejected. 
    

    any advice would be appreciated



    ------------------------------
    Jasmin
    ------------------------------