<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users can't send mail after upgrade to 8.0.5 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513040#M2980</link>
    <description>&lt;P&gt;Can you try re-entering the password in email settings.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Aug 2020 15:53:06 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-08-07T15:53:06Z</dc:date>
    <item>
      <title>Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513037#M2979</link>
      <description>&lt;P&gt;Hi all, after upgrade to 8.0.5 from 7.2.6 all my users can't send mail using sendemail.py because they don't have access to mail settings:&lt;/P&gt;
&lt;P&gt;ERROR sendemail:1370 - Could not get email credentials from splunk, using no credentials. Error: [HTTP 403] Client is not authorized to perform requested action; &lt;A href="https://127.0.0.1:8089/services/admin/alert_actions/email" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/services/admin/alert_actions/email&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I've already checked that list_settings is added to roles. If I add &lt;STRONG&gt;admin_all_objects&lt;/STRONG&gt; users can send but I don't want to add that capability to all users.&lt;/P&gt;
&lt;P&gt;Is there other capability to add other that list_settings to enable user to send mail?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 22:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513037#M2979</guid>
      <dc:creator>netspin</dc:creator>
      <dc:date>2020-09-02T22:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513040#M2980</link>
      <description>&lt;P&gt;Can you try re-entering the password in email settings.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 15:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513040#M2980</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-07T15:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513254#M2986</link>
      <description>&lt;P&gt;I think credential is correctly stored as if I login using admin mail is working.&lt;/P&gt;&lt;P&gt;The issue is with user without admin priviledge (but with list_settings capabilities).&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 06:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513254#M2986</guid>
      <dc:creator>netspin</dc:creator>
      <dc:date>2020-08-10T06:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513698#M3010</link>
      <description>&lt;P&gt;I have the same problem. If I add "list_settings" to role user. Then users can send mail, but get an error in&amp;nbsp;python.log:&lt;/P&gt;&lt;P&gt;sendemail:1370 - Could not get email credentials from splunk, using no credentials. Error: [HTTP 403] Client is not authorized to perform requested action; &lt;A href="https://127.0.0.1:8089/services/admin/alert_actions/email" target="_blank"&gt;https://127.0.0.1:8089/services/admin/alert_actions/email&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 11:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/513698#M3010</guid>
      <dc:creator>mne</dc:creator>
      <dc:date>2020-08-12T11:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/514688#M3055</link>
      <description>Me too, in Splunk Cloud.</description>
      <pubDate>Tue, 18 Aug 2020 12:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/514688#M3055</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2020-08-18T12:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517148#M3195</link>
      <description>&lt;P&gt;Same issue here. After upgrading to 8.0.5 alerts that were working, don't work unless i change the owner to an admin user.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 04:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517148#M3195</guid>
      <dc:creator>matthewroberson</dc:creator>
      <dc:date>2020-09-01T04:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517577#M3217</link>
      <description>&lt;P&gt;I see now that this is a &lt;A title="Known Issues" href="https://docs.splunk.com/Documentation/Splunk/8.0.5/ReleaseNotes/Knownissues" target="_blank" rel="noopener"&gt;Highlighted Issue&lt;/A&gt; in the release notes. Hope they fix it soon...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 20:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517577#M3217</guid>
      <dc:creator>matthewroberson</dc:creator>
      <dc:date>2020-09-02T20:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517638#M3222</link>
      <description>&lt;P&gt;Fixed issue in 8.0.6&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2020-08-26&lt;/TD&gt;&lt;TD&gt;SPL-194243, SPL-193332&lt;/TD&gt;&lt;TD&gt;After upgrade to version 8.0.5, the splunk user needs the "admin_all_objects" capability to send email alert&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 03 Sep 2020 05:35:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/517638#M3222</guid>
      <dc:creator>lakromani</dc:creator>
      <dc:date>2020-09-03T05:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/542157#M5112</link>
      <description>&lt;P&gt;same here, I am now in version 8.1.2, no solution yet. Reported (again) to support for a final solution.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In my opnion this is nothing else than a security breach. Security for regular user is "wide open" if you want use this sendemail function. This issue has already a long history in version and the the lack of urgency begins to worry me. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 13:19:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/542157#M5112</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-03T13:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545778#M5421</link>
      <description>&lt;P&gt;I cant find anyone with this issue on version 7.12, but it looks to be slightly different&lt;BR /&gt;&lt;BR /&gt;sendemail:460 - Connection unexpectedly closed while sending mail to:&amp;lt;Email&amp;gt;&lt;BR /&gt;&lt;BR /&gt;this is when you send a test email from the export PDF "send test email" link&lt;/P&gt;&lt;P&gt;2021-03-29 09:25:09,687 +1300 INFO sendemail:1296 - Generated PDF for email&lt;BR /&gt;2021-03-29 09:25:15,035 +1300 ERROR sendemail:137 - Sending email. subject="Splunk Dashboard: &amp;lt;Name&amp;gt;", results_link="None", recipients="[u'&amp;lt;User&amp;gt;']", server="smtp.office365.com:587"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When sending as admin It works as I assume that is needs to pass on the creds (which you cant specify when using "send test email" ) and only works when testing it from a Admin account.&lt;BR /&gt;&lt;BR /&gt;We are planning to go to the cloud so updating to the 8.0.6 (so called fixed version) it not on the cards and someone says its an issue in the cloud which i hope was resolved?&lt;BR /&gt;&lt;BR /&gt;any work around for now?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 21:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545778#M5421</guid>
      <dc:creator>grant_c</dc:creator>
      <dc:date>2021-03-28T21:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545779#M5422</link>
      <description>&lt;P class="lia-align-left"&gt;NVM I found some interesting information&lt;/P&gt;&lt;P class="lia-align-left"&gt;For a number of version now the requirements are&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mw-headline"&gt;User role configuration for PDF delivery&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The following capabilities are required for PDF delivery scheduling.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;schedule_search&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;admin_all_objects. This capability is required if the mail host requires login credentials.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="li_content"&gt;list_settings&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/Emailnotification" target="_blank" rel="noopener"&gt;Email notification action - Splunk Documentation&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;so the only way to "Allow" this is to give a role this&amp;nbsp;capability (rather not) or setup a local SMTP to forward the email to O365&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 22:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545779#M5422</guid>
      <dc:creator>grant_c</dc:creator>
      <dc:date>2021-03-28T22:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545861#M5429</link>
      <description>&lt;P&gt;FyI: Recent answer from Splunk Support:&lt;BR /&gt;&lt;BR /&gt;Previously mentioned bugs, SPL-194202 being one of them addressed the issue where alerts created by a user with role "user" would not be sent if they didn't have the admin_all_objects capability - this has been fixed. This is different from using the "sendemail" command directly from any search - I'm afraid this is working as documented (it will not work unless the previously discussed capabilities are added to the user role), please see the documentation on that:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#Define_an_email_notification_action_for_an_alert_or_scheduled_report" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#Define_an_email_notification_action_for_an_alert_or_scheduled_report&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#User_role_configuration_for_PDF_delivery" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#User_role_configuration_for_PDF_delivery&lt;/A&gt; (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Alert/Emailnotification#User_role_configuration_for_PDF_delivery" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Alert/Emailnotification#User_role_configuration_for_PDF_delivery&lt;/A&gt;)&lt;BR /&gt;&lt;BR /&gt;If you are sending an email notification to a server that requires SMTP authentication, you must have the admin role assigned. (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#Use_a_search_command_to_" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification#Use_a_search_command_to_&lt;/A&gt;... (truncated, see original email for full text)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Conclusion: this will not be fixed in any version because it works as documented &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 14:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545861#M5429</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-29T14:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error "sendemail:1370": Users can't send mail after upgrade from 7.2.6 to 8.0.5.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545863#M5430</link>
      <description>&lt;P&gt;created an Idea on:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ideas.splunk.com/ideas/ESSID-I-97" target="_blank"&gt;sole the issue: sendemail without the cost of a security | Ideas (splunk.com)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately I have only 1 Votes yet &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; - so a solution soon is not expected&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 14:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/545863#M5430</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-29T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558179#M6301</link>
      <description>&lt;P&gt;we're experiencing this issue, too? Did you find a fix?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 15:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558179#M6301</guid>
      <dc:creator>w531t4</dc:creator>
      <dc:date>2021-07-02T15:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558185#M6302</link>
      <description>&lt;P&gt;&lt;U&gt;We upgraded to 8.0.6 and that resolved the issue.&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 16:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558185#M6302</guid>
      <dc:creator>matthewroberson</dc:creator>
      <dc:date>2021-07-02T16:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Users can't send mail after upgrade to 8.0.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558252#M6305</link>
      <description>&lt;P&gt;I created an idea some time ago for this issue, see&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://ideas.splunk.com/ideas/ESSID-I-97" target="_blank"&gt;sole the issue: sendemail without the cost of a security | Ideas (splunk.com)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It appears to be in a stage of consideration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 08:30:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Getting-error-quot-sendemail-1370-quot-Users-can-t-send-mail/m-p/558252#M6305</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-07-04T08:30:50Z</dc:date>
    </item>
  </channel>
</rss>

