Alerting

Email Alert Issue sending via AWS SES

gearoidrogers
New Member

hi folks

using splunk 7.1.1 and we're having issues sending email alerts to AWS SES - when we send via a search string the mail works just fine. I've also modified the sendemail.py file to enable TLS. Has anyone successfully managed to get this working as I have not seen any splunk answers which has solved the automatic alert issue, only when sending via a search

Blockquote

==> var/log/splunk/python.log <==
2019-08-15 15:13:02,306 +0000 ERROR sendemail:140 - Sending email. subject="Splunk Alert: Amazon Client Exception", results_link="http://aws-domain:8000/app/search/@go?sid=scheduler__gearoidr__search__RMD56da3f171ecf1725d_at_15658...", recipients="[u'[email protected]']", server="email-smtp.us-east-1.amazonaws.com:587"
2019-08-15 15:13:02,306 +0000 ERROR sendemail:463 - (554, "Transaction failed: User name is missing: 'splunk'.") while sending mail to: [email protected]

==> var/log/splunk/splunkd.log <==
08-15-2019 15:13:02.306 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=http://aws-domain:8000/app/search/@go?sid=scheduler__gearoidr__search__RMD56da3f171ecf1725d_at_15658..." "ssname=Amazon Client Exception" "graceful=True" "trigger_time=1565881981" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler_gearoidrsearch_RMD56da3f171ecf1725d_at_1565881980_2/results.csv.gz"': ERROR:root:(554, "Transaction failed: User name is missing: 'splunk'.") while sending mail to: [email protected]
08-15-2019 15:13:13.160 +0000 INFO TcpOutputProc - Connected to idx=10.0.26.132:9997, pset=0, reuse=0.

Blockquote

Blockquote

The logs from a successful search email event
==> var/log/splunk/python.log <==
2019-08-15 15:28:55,535 +0000 INFO sendemail:1299 - Generated PDF for email
2019-08-15 15:28:55,880 +0000 INFO sendemail:137 - Sending email. subject="Here is an email notification", results_link="None", recipients="[u'[email protected]']", server="email-smtp.us-east-1.amazonaws.com:587"

Blockquote

0 Karma

pavan_fwd
Observer

We are also facing the same issue with latest splunk version 9.01
I have tried using port:465 with enable ssl as well.

 

0 Karma

lbadmin
Engager

Hi, did you manage to get a solution to this issue? Same thing happening to me after upgrading from Splunk to Splunk 8 to 9.

Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...