<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: E-mail alerts stopped working since 6.6 upgrade for some users in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/520012#M9692</link>
    <description>&lt;P&gt;This is the solution from Splunk as well:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkcommunities.force.com/customers/apex/ArticleDetailPage?URLName=Scheduled-Search-Alert-not-Triggering-Emails" target="_blank"&gt;https://splunkcommunities.force.com/customers/apex/ArticleDetailPage?URLName=Scheduled-Search-Alert-not-Triggering-Emails&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 20:44:00 GMT</pubDate>
    <dc:creator>andygerberkp</dc:creator>
    <dc:date>2020-09-16T20:44:00Z</dc:date>
    <item>
      <title>E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295973#M9320</link>
      <description>&lt;P&gt;Following upgrade to Splunk Enterprise 6.6, some of my users' scheduled e-mail reports are no longer working.   Admins seem fine, but others not so.   Seeing errors like this in python.log:&lt;/P&gt;

&lt;P&gt;2017-05-16 09:22:43,543 +0100 ERROR ssl_context:638 - SSLHelper.getServerSettings Could not access or parse sslConfig stanza of server.conf. Error=[HTTP 403] Client is not authorized to perform requested action; &lt;A href="https://127.0.0.1:8089/services/configs/conf-server/sslConfig"&gt;https://127.0.0.1:8089/services/configs/conf-server/sslConfig&lt;/A&gt; &lt;BR /&gt;
2017-05-16 09:22:43,543 +0100 ERROR sendemail:137 - Sending email. subject=“#######”, server="127.0.0.1:25" &lt;BR /&gt;
2017-05-16 09:22:43,543 +0100 ERROR sendemail:443 - 'rootCAPath' while sending mail to: ########&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 14:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295973#M9320</guid>
      <dc:creator>tin_fish</dc:creator>
      <dc:date>2017-05-16T14:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295974#M9321</link>
      <description>&lt;P&gt;You need to give your users the 'list_settings' capability; that was introduced in Splunk 6.6 part of Common Criteria  (ISO/IEC 15408) compliance, so alert-sending has access to SSL configurations.  &lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 14:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295974#M9321</guid>
      <dc:creator>mafisher_splunk</dc:creator>
      <dc:date>2017-05-16T14:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295975#M9322</link>
      <description>&lt;P&gt;where to give "users the 'list_settings' capability"&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 19:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295975#M9322</guid>
      <dc:creator>mugundanava</dc:creator>
      <dc:date>2017-05-25T19:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295976#M9323</link>
      <description>&lt;P&gt;You can add capabilities under Roles.  &lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 08:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295976#M9323</guid>
      <dc:creator>mafisher_splunk</dc:creator>
      <dc:date>2017-05-26T08:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295977#M9324</link>
      <description>&lt;P&gt;I have followed the suggested resolution with no success. Is there any other suggestions for restoring Emailing alerts (using TLS) after upgrade to 6.6.2? Email isn't working for Admin, Power users, or Users. &lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 17:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295977#M9324</guid>
      <dc:creator>hharris</dc:creator>
      <dc:date>2017-07-12T17:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295978#M9325</link>
      <description>&lt;P&gt;Works. Thanks for the info.&lt;/P&gt;

&lt;P&gt;(Not really happy, though, to give our normal users a capability which, by default, is admin-only...)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 10:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295978#M9325</guid>
      <dc:creator>usd0872</dc:creator>
      <dc:date>2017-12-19T10:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295979#M9326</link>
      <description>&lt;P&gt;It seems like mafisher has posted the resolution for this issue.  We upgraded to version 7 and had the same issue with failed email alerts.  Splunk should have documented this change to capabilities in the README.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 19:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/295979#M9326</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2018-04-09T19:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/507858#M9327</link>
      <description>&lt;P&gt;According to the roles/capabilities definition of "list_settings" this gives users 'Lets the user list and view server and introspection settings such as the server name, log levels, etc'.&amp;nbsp; Since this is default an admin capability, how much of a vulnerability is this if a user is allowed the same capability?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 14:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/507858#M9327</guid>
      <dc:creator>gstultz_splunk</dc:creator>
      <dc:date>2020-07-07T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: E-mail alerts stopped working since 6.6 upgrade for some users</title>
      <link>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/520012#M9692</link>
      <description>&lt;P&gt;This is the solution from Splunk as well:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkcommunities.force.com/customers/apex/ArticleDetailPage?URLName=Scheduled-Search-Alert-not-Triggering-Emails" target="_blank"&gt;https://splunkcommunities.force.com/customers/apex/ArticleDetailPage?URLName=Scheduled-Search-Alert-not-Triggering-Emails&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 20:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/E-mail-alerts-stopped-working-since-6-6-upgrade-for-some-users/m-p/520012#M9692</guid>
      <dc:creator>andygerberkp</dc:creator>
      <dc:date>2020-09-16T20:44:00Z</dc:date>
    </item>
  </channel>
</rss>

