<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email action for alerts no longer works since Splunk 7.3.6 in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552585#M10521</link>
    <description>&lt;P&gt;Hi Support, did any body a solution for it. I Just upgrade my splunk from 7.2.2 to 7.3 it works fine, but after this version the email alerts doesn't work. Did anybody able to resolve this issue. Please, let me know ASAP. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 21 May 2021 18:43:33 GMT</pubDate>
    <dc:creator>muhammadamir</dc:creator>
    <dc:date>2021-05-21T18:43:33Z</dc:date>
    <item>
      <title>Email action for alerts no longer works since Splunk 7.3.6</title>
      <link>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/505719#M9155</link>
      <description>&lt;P&gt;Last week we upgraded our Splunk-cluster from version 7.3.5 to 7.3.6. Since that moment, alerts that are triggered no longer are able to send mail.&lt;/P&gt;&lt;P&gt;The _internal index shows an event stating "&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sendemail:461&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;rootCAPath&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;while&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sending&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;mail&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;to&lt;/SPAN&gt;: xxx@xx&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;From other posts it seems to be required to add the list_settings capability to our user roles. However, prior to the update we have had no problems with alert mails without adding this capability to user roles. The release notes for version 7.3.6 don't mention any fix or change in this regard.&lt;/P&gt;&lt;P&gt;Since the documentation is not quite clear about the impact of adding this capability to a user role (what additional possibilities are available to users with this capability) and this didn't seem to be required up until version 7.3.5 we would like to be sure this capability won't harm our setup&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 11:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/505719#M9155</guid>
      <dc:creator>HumanPrinter</dc:creator>
      <dc:date>2020-06-23T11:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Email action for alerts no longer works since Splunk 7.3.6</title>
      <link>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552585#M10521</link>
      <description>&lt;P&gt;Hi Support, did any body a solution for it. I Just upgrade my splunk from 7.2.2 to 7.3 it works fine, but after this version the email alerts doesn't work. Did anybody able to resolve this issue. Please, let me know ASAP. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 18:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552585#M10521</guid>
      <dc:creator>muhammadamir</dc:creator>
      <dc:date>2021-05-21T18:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Email action for alerts no longer works since Splunk 7.3.6</title>
      <link>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552586#M10522</link>
      <description>&lt;P&gt;Hi. I had the same question of Splunk support.&amp;nbsp; I had asked ffor documentation clarification but it doesn't seem to have made it into this documentation&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/authorizeconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/authorizeconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Support told me that&amp;nbsp;&lt;SPAN&gt;list_settings allows a user to have access to settings endpoint.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local /services/server/settings&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;We added it for our users.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 19:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552586#M10522</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2021-05-21T19:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Email action for alerts no longer works since Splunk 7.3.6</title>
      <link>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552593#M10523</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/126711"&gt;@muhammadamir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a known issue with v7.3.6; we ran into it at my company when we upgraded.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To resolve the problem you'll need to add the "admin_all_objects" capability to anyone that needs to send an email alert. There's more info about the issue in the release notes:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.6/ReleaseNotes/Knownissues#Highlighted_issues" target="_blank" rel="noopener"&gt;Known issues - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 20:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-action-for-alerts-no-longer-works-since-Splunk-7-3-6/m-p/552593#M10523</guid>
      <dc:creator>lweiss</dc:creator>
      <dc:date>2021-05-21T20:55:08Z</dc:date>
    </item>
  </channel>
</rss>

