<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Email Settings | TLS Handshake in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417589#M7282</link>
    <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;

&lt;P&gt;I am trying to setup a TLs communication btw Splunk Entreprise and an email server for sending alerts. Based on three available options - None | SSL | TLS, only none is working properly. &lt;/P&gt;

&lt;P&gt;when chose TLS I received the following error "ERROR:root:STARTTLS extension not supported by server. while sending mail to"&lt;/P&gt;

&lt;P&gt;01-22-2019 17:57:57.138 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=&lt;A href="https://uh0014:8443/app/search/@go?sid=rt_scheduler__vile__search__RMD50843376f462c8b90_at_1548179587_6.45" target="_blank"&gt;https://uh0014:8443/app/search/@go?sid=rt_scheduler__vile__search__RMD50843376f462c8b90_at_1548179587_6.45&lt;/A&gt;" "ssname=Errors reported (Real Time)" "graceful=True" "trigger_time=1548179876" results_file="/opt/splunk/var/run/splunk/dispatch/rt_scheduler_&lt;EM&gt;vile&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD50843376f462c8b90_at_1548179587_6.45/results.csv.gz"':  ERROR:root:STARTTLS extension not supported by server. while sending mail to:&lt;/P&gt;

&lt;P&gt;On alert_action.conf file I have the following&lt;BR /&gt;
[email]&lt;BR /&gt;
mailserver = smtp.XXXXX&lt;BR /&gt;
pdf.header_left = none&lt;BR /&gt;
pdf.header_right = none&lt;BR /&gt;
use_tls = 1&lt;BR /&gt;
sslVersions = tls1.2&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
use_ssl = 0&lt;BR /&gt;
from = noreply_siem@XXXXX&lt;BR /&gt;
reportPaperSize = a4&lt;/P&gt;

&lt;P&gt;Any tip?&lt;/P&gt;

&lt;P&gt;Sincerely&lt;/P&gt;

&lt;P&gt;VML&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:52:12 GMT</pubDate>
    <dc:creator>socespap</dc:creator>
    <dc:date>2020-09-29T22:52:12Z</dc:date>
    <item>
      <title>Email Settings | TLS Handshake</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417589#M7282</link>
      <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;

&lt;P&gt;I am trying to setup a TLs communication btw Splunk Entreprise and an email server for sending alerts. Based on three available options - None | SSL | TLS, only none is working properly. &lt;/P&gt;

&lt;P&gt;when chose TLS I received the following error "ERROR:root:STARTTLS extension not supported by server. while sending mail to"&lt;/P&gt;

&lt;P&gt;01-22-2019 17:57:57.138 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=&lt;A href="https://uh0014:8443/app/search/@go?sid=rt_scheduler__vile__search__RMD50843376f462c8b90_at_1548179587_6.45" target="_blank"&gt;https://uh0014:8443/app/search/@go?sid=rt_scheduler__vile__search__RMD50843376f462c8b90_at_1548179587_6.45&lt;/A&gt;" "ssname=Errors reported (Real Time)" "graceful=True" "trigger_time=1548179876" results_file="/opt/splunk/var/run/splunk/dispatch/rt_scheduler_&lt;EM&gt;vile&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD50843376f462c8b90_at_1548179587_6.45/results.csv.gz"':  ERROR:root:STARTTLS extension not supported by server. while sending mail to:&lt;/P&gt;

&lt;P&gt;On alert_action.conf file I have the following&lt;BR /&gt;
[email]&lt;BR /&gt;
mailserver = smtp.XXXXX&lt;BR /&gt;
pdf.header_left = none&lt;BR /&gt;
pdf.header_right = none&lt;BR /&gt;
use_tls = 1&lt;BR /&gt;
sslVersions = tls1.2&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
use_ssl = 0&lt;BR /&gt;
from = noreply_siem@XXXXX&lt;BR /&gt;
reportPaperSize = a4&lt;/P&gt;

&lt;P&gt;Any tip?&lt;/P&gt;

&lt;P&gt;Sincerely&lt;/P&gt;

&lt;P&gt;VML&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:52:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417589#M7282</guid>
      <dc:creator>socespap</dc:creator>
      <dc:date>2020-09-29T22:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Email Settings | TLS Handshake</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417590#M7283</link>
      <description>&lt;P&gt;Same error here, unable to send any emails from Splunk Enterprise.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 04:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417590#M7283</guid>
      <dc:creator>orion44</dc:creator>
      <dc:date>2019-02-18T04:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Email Settings | TLS Handshake</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417591#M7284</link>
      <description>&lt;P&gt;Hi, did you resolve this?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 08:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417591#M7284</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2019-09-17T08:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Email Settings | TLS Handshake</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417592#M7285</link>
      <description>&lt;P&gt;Hi VML,&lt;/P&gt;

&lt;P&gt;I had a similar issue when using Office 365 SMTP settings. Usually it is enough to specify &lt;STRONG&gt;smtp.office365.com&lt;/STRONG&gt; however I got the same error as yourself. Try adding the port number at the end of the address within Email Settings.&lt;/P&gt;

&lt;P&gt;e.g. &lt;STRONG&gt;smtp.office365.com:587&lt;/STRONG&gt; (587 is default). For Office 365 this works with TLS enabled. &lt;/P&gt;

&lt;P&gt;Best wishes,&lt;/P&gt;

&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 09:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Email-Settings-TLS-Handshake/m-p/417592#M7285</guid>
      <dc:creator>driva</dc:creator>
      <dc:date>2020-01-07T09:11:29Z</dc:date>
    </item>
  </channel>
</rss>

