<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408786#M173566</link>
    <description>&lt;P&gt;You need to have admin role together with list_settings capability in order to send alert email when SMTP auth is used.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jan 2019 07:58:08 GMT</pubDate>
    <dc:creator>daniel_splunk</dc:creator>
    <dc:date>2019-01-18T07:58:08Z</dc:date>
    <item>
      <title>Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408785#M173565</link>
      <description>&lt;P&gt;Have defined a new non-admin user and  already add list_settings capability as instructed by the Splunk document here.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Alert/Emailnotification"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Alert/Emailnotification&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But still failed to send alert when mail server is using SMTL auth.&lt;/P&gt;

&lt;P&gt;Here is the python.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-09-17 15:21:51,268 +0800 DEBUG ssl_context:444 - createSSLContext sslVersions [16] commonNameList [None] altNameList [None] validatePeerCert [0] rootCAPath [None] isClientContext [True] cipherSuite [ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256]
2018-09-17 15:21:51,295 +0800 ERROR sendemail:137 - Sending email. subject="Splunk testing", results_link="None", recipients="[u'user1@abc.com.hk']", server="172.21.184.4"

2018-09-17 15:21:51,295 +0800 ERROR sendemail:452 - {u'user1@abc.com.hk': (530, 'SMTP authentication is required.')} while sending mail to: user1@abc.com.hk
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408785#M173565</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2019-01-18T07:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408786#M173566</link>
      <description>&lt;P&gt;You need to have admin role together with list_settings capability in order to send alert email when SMTP auth is used.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408786#M173566</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2019-01-18T07:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408787#M173567</link>
      <description>&lt;P&gt;In my testing, you only needed to have the "list_settings" capability with a "user" role in order for this to work. (Using Splunk Cloud 7.2.9).&lt;/P&gt;

&lt;P&gt;See this link: &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.0.0/Alert/Emailnotification"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.0.0/Alert/Emailnotification&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This section: "Define an email notification for an alert or scheduled report"&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 20:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/408787#M173567</guid>
      <dc:creator>scorrie_splunk</dc:creator>
      <dc:date>2019-12-18T20:42:11Z</dc:date>
    </item>
    <item>
      <title>Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/521953#M173568</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/153752"&gt;@daniel_splunk&lt;/a&gt;&amp;nbsp; Is there no other way to allow non-admin users to send alert emails when SMTP authentication is required?&amp;nbsp; Are there any other capabilities from the "admin" role that I can assign to the "user" role in order to allow regular users to send email?&lt;/P&gt;&lt;P&gt;I just upgraded from Splunk Enterprise 7.3.3 to 8.05, and one of my non-admin users said that his saved alerts used to be able to send him emails when we were on 7.3.3.&amp;nbsp; Nothing has changed with his Splunk role or the SMTP authentication requirement between our pre- and post-Splunk upgrade.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/521953#M173568</guid>
      <dc:creator>leeraym</dc:creator>
      <dc:date>2020-09-29T10:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/522394#M173569</link>
      <description>&lt;P&gt;If your email account is SMTP auth enabled, you need to have admin role in order to read the email auth details such as password.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 03:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/522394#M173569</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2020-10-01T03:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Non-admin user with list_settings capability failed to send alert email when mail sever use SMTP auth.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/529920#M173570</link>
      <description>&lt;P&gt;So, if I understand how sendemail works when SMTP auth is required, a user needs the "admin_all_objects" capability" in order to read auth_username and auth_password from alert_actions.&lt;/P&gt;&lt;P&gt;This means regular users can't send email, as the credentials get passed to SMTP server with null values. These users generally see something like this:&lt;/P&gt;&lt;P&gt;command="sendemail", Connection unexpectedly closed while sending mail to: &lt;A href="mailto:somebody@something.com" target="_blank"&gt;somebody@something.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Is this a feature or a bug?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 14:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Non-admin-user-with-list-settings-capability-failed-to-send/m-p/529920#M173570</guid>
      <dc:creator>kscher</dc:creator>
      <dc:date>2020-11-18T14:31:14Z</dc:date>
    </item>
  </channel>
</rss>

