<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sendemail command only works with capacility 'admin_all_objects' in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/541973#M8804</link>
    <description>&lt;P&gt;update from support:&lt;/P&gt;&lt;P&gt;-==-=-=-=-&lt;BR /&gt;I hope you are doing well. I was reviewing the know issues list and I found the issue number SPL-138647, See the link below for more information.&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know if it worked for you.&lt;/P&gt;&lt;P&gt;-==-==-==-&lt;/P&gt;&lt;P&gt;What I did :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;On our none-production instance/machine (rather a fresh installation), I did:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Changed my “alert_action.conf” file to this (see below) : (as explained in the document and is less secure as I understand from that document) – named: Workaround&lt;/LI&gt;&lt;LI&gt;Removed the “Admin_All_Ojects” capability from the Test user-role&lt;/LI&gt;&lt;LI&gt;No success ☹&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[email]&lt;/P&gt;&lt;P&gt;Auth_password = xx&lt;/P&gt;&lt;P&gt;auth_username =xx&lt;/P&gt;&lt;P&gt;from =xx&lt;/P&gt;&lt;P&gt;mailserver = smtp.office365.com:587&lt;/P&gt;&lt;P&gt;sslVersions = *,-ssl2&lt;/P&gt;&lt;P&gt;cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH&lt;/P&gt;&lt;P&gt;Unfortunately no success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 14:24:57 GMT</pubDate>
    <dc:creator>apietersen</dc:creator>
    <dc:date>2021-03-02T14:24:57Z</dc:date>
    <item>
      <title>Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540855#M8787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Since some version (now using 8.1.2) I have trouble to use the 'sendemail' command in a search (dashboard/form) for user that have the standard user-roles. This issue is troubling me for almost&amp;nbsp; 1.5 year now.&amp;nbsp;&amp;nbsp;Of course I am aware of the need to select 'list_settings' but had never a results. When selecting&amp;nbsp;'admin_all_objects' in the standard user-role is succesful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But using the 'admin_all_objects' for standard user is nothing but a security breach. That can not be the solution , so what do I miss here?&lt;/P&gt;&lt;P&gt;An why does Splunk not create a special and straightforward capability for this 'sendemail' command?&lt;/P&gt;&lt;P&gt;Ashley Pietersen&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 15:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540855#M8787</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-02-22T15:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540860#M8788</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;it is a known issue that affect some versions and should be fixed as of now&lt;/P&gt;&lt;P&gt;see &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.7/ReleaseNotes/Fixedissues#Splunk_Enterprise_7.3.7.1" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.7/ReleaseNotes/Fixedissues#Splunk_Enterprise_7.3.7.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;8.1.2 should have the fix I think.&lt;/P&gt;&lt;P&gt;If not the case, please open a support case and have the support investigate with you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 16:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540860#M8788</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2021-02-22T16:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540865#M8789</link>
      <description>&lt;P&gt;Thanks maraman_splunk,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Unfortunately Splunk support does not respond ! They advised me earlier to select 'admin_all_objects' to use the command anyway. Because I really need the sendemail for some customer. Since v8.0 the other alternative was the option 'sendresults'&amp;nbsp; but that was also not wokring anymore. Hoped this would solved in next version, but after 8.1.2 I am till struggling with this issue and have my 'door wide open' since because of this.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 16:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/540865#M8789</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-02-22T16:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/541471#M8801</link>
      <description>&lt;P&gt;last update Wednesday from Splunk support:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"... just want to give you an update about the case, we are still working to find a solution, I engaged additional support to assist us with the issue, as soon as we have more information we will let you know. Please feel free to contact us if you have any questions."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Keep you posted...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 08:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/541471#M8801</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-02-26T08:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/541973#M8804</link>
      <description>&lt;P&gt;update from support:&lt;/P&gt;&lt;P&gt;-==-=-=-=-&lt;BR /&gt;I hope you are doing well. I was reviewing the know issues list and I found the issue number SPL-138647, See the link below for more information.&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know if it worked for you.&lt;/P&gt;&lt;P&gt;-==-==-==-&lt;/P&gt;&lt;P&gt;What I did :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;On our none-production instance/machine (rather a fresh installation), I did:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Changed my “alert_action.conf” file to this (see below) : (as explained in the document and is less secure as I understand from that document) – named: Workaround&lt;/LI&gt;&lt;LI&gt;Removed the “Admin_All_Ojects” capability from the Test user-role&lt;/LI&gt;&lt;LI&gt;No success ☹&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[email]&lt;/P&gt;&lt;P&gt;Auth_password = xx&lt;/P&gt;&lt;P&gt;auth_username =xx&lt;/P&gt;&lt;P&gt;from =xx&lt;/P&gt;&lt;P&gt;mailserver = smtp.office365.com:587&lt;/P&gt;&lt;P&gt;sslVersions = *,-ssl2&lt;/P&gt;&lt;P&gt;cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH&lt;/P&gt;&lt;P&gt;Unfortunately no success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 14:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/541973#M8804</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-02T14:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542098#M8806</link>
      <description>&lt;P&gt;update from splunk support:&lt;/P&gt;&lt;P&gt;-=-=-=-=&lt;BR /&gt;I hope you are doing well. I was reviewing the know issues list and I found the issue number SPL-138647, See the link below for more information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know if it worked for you.&lt;/P&gt;&lt;P&gt;-=-=-=-=&lt;/P&gt;&lt;P&gt;unfortunately no success yet&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 08:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542098#M8806</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-03T08:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542105#M8807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It seems to be an issue with a long history in known issues - even from version 6.6&amp;nbsp; so I understand. What should I do next? Any tips?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 08:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542105#M8807</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-03T08:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542200#M8811</link>
      <description>&lt;P&gt;Just installed a complete fresh Splunk instance v8.1.2 from scratch on w2019 - no adjustments made. Only configured the smtp server setting. Tested it with admin account: sendemail works (but this has 'admin_all_objects' as a default capability.&lt;/P&gt;&lt;P&gt;created a test account with standard user-role. (defaults without the 'admin_all_objects' capability). Sendemail does not werk without any visible error, although the search itself results in a timestamp&lt;BR /&gt;&lt;BR /&gt;search in serach&amp;amp;reporting used:&lt;BR /&gt;&lt;BR /&gt;| makeresults&lt;BR /&gt;| sendemail to="x.yyyy@aaaaa.bb", from="y.yxxxx@bbbbb.aa"" ,&lt;BR /&gt;subject="test-message", sendresults=false inline=true format=raw content_type=html&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;results in python.log:&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File ""D:\Program Files\Splunk\etc\apps\search\bin\sendemail.py"", line 1593, in &amp;lt;module&amp;gt;&lt;BR /&gt;results = sendEmail(results, settings, keywords, argvals)&lt;BR /&gt;File ""D:\Program Files\Splunk\etc\apps\search\bin\sendemail.py"", line 376, in sendEmail&lt;BR /&gt;if ssContent['action.email.sendresults'] or ssContent['action.email.sendpdf'] or ssContent['action.email.sendcsv']:&lt;BR /&gt;KeyError: 'action.email.sendpdf'&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 16:07:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/542200#M8811</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-03T16:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/543382#M8847</link>
      <description>&lt;P&gt;Hi Ashley,&lt;BR /&gt;&lt;BR /&gt;Message frome Splunk Support:&lt;BR /&gt;&lt;BR /&gt;.. According to the engineering department, the fix will be released in Splunk 8.1.3. Let me know if it worked for you...&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 14:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/543382#M8847</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-11T14:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command only works with capacility 'admin_all_objects'</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/544741#M8906</link>
      <description>&lt;P&gt;This issue was reported by support to be solved in v8.1.3 . Unfortunately this issue is still there in v8.1.3&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 07:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command-only-works-with-capacility-admin-all-objects/m-p/544741#M8906</guid>
      <dc:creator>apietersen</dc:creator>
      <dc:date>2021-03-22T07:41:10Z</dc:date>
    </item>
  </channel>
</rss>

