Other Usage

Why is Splunk send email function not working (version 9.1.0.2)?

ThuLe
Explorer

Hello,

We're using Splunk  Enterprise version 9.1.0.2 and trying to configure Splunk to send email alerts but cannot make it work. We've tried both Gmail and O365, here are the errors:

1. Email settings: Mail host: smtp.gmail.com:587Enable TLS, enter Username and password (we use app password for smtp.gmail.com)

--> Errorsendemail:561 - (530, b'5.7.0 Authentication Required. Learn more at\n5.7.0 https://support.google.com/mail/?p=WantAuthError 5-20020a17090a1a4500b00274e610dbdasm2199058pjl.8 - gsmtp', 'sender@gmail.com') while sending mail to: receive@....

2. Email settings: Mail host: smtp.office365.com:587, Enable TLS, enter Username and password (username and password can login to Outlook successfully)

--> Error: sendemail:561 - (530, b'5.7.57 Client not authenticated to send mail. [SGAP274CA0001.SGPP274.PROD.OUTLOOK.COM 2023-09-21T02:01:45.399Z 08DBB9CB1E03821B]', 'sender@senderdomain.com') while sending mail to: receive@....

 

Please support.

Thank you.

Labels (3)
Tags (1)

O815163
Loves-to-Learn Lots

After upgrading to v91.1. I also ran into that issue, but only for Windows machines that had Splunk Enterprise installed. The Linux installations were not affected.

I fixed it by replacing the ...\Splunk\etc\apps\search\bin\sendemail.py with an older version. Now I am getting integrity check errors, but e-mail alerts work fine.

 

There is another post that says this issue might be fixed in v9.1.2. Let's see.. https://community.splunk.com/t5/Splunk-Enterprise/What-is-happening-in-Splunk-Enterprise-V9-1-0-1/m-...

0 Karma

marioespbaires
Loves-to-Learn

Hello! where did you find the old sendemail.py?

0 Karma

itbairesdev
Engager

I got the same error even when using the standard password and app-password, using TLS or SSL.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...