Reporting

Email alert action not sending in 7.2.4 (dev/test license)

chanfoli
Builder

I just did a fresh install of 7.2.4 and installed my dev/test license. I am trying to test email alert functionality, which worked on this system when a previous version was installed. The search fires and appears to trigger the alert action but it looks like sendemail is failing. This is the message in the python.log:

2019-02-08 15:45:01,734 -0500 ERROR sendemail:1397 - [HTTP 404] https://127.0.0.1:8089/servicesNS/admin/search/saved/searches/Splunk%20Web%20Login?output_mode=json

I am not sure if this a bug which needs to have support check into it, or if it is due to using a dev/test license under this version. I did not have this issue with a dev/test license under older versions. I did set up this instance with a different admin username than admin however, so I am not sure if this is related.

0 Karma

umlsasec
New Member

Unfortunately, this appears to a limitation with the dev license. With identical settings in my prod Splunk with enterprise license, it works just fine, but the dev server returns the same 404 error you're getting.

This is the second time I've spent hours chasing an issue only to realize it is an unpublished license limitation. 😕

0 Karma

ShawnWarner7
New Member

I'm seeing the same issue. Did you ever get this resolved?

0 Karma

jkat54
SplunkTrust
SplunkTrust

404 status code means the page is not found. In this case the URL seems to suggest its looking for the json output of a search named “Splunk Web Login”.

Is there a search named “Splunk Web Login” in savedsearches.conf in $splunk_home/etc/apps/search/default/

Or

$splunk_home/etc/apps/search/local/

?

0 Karma

adonio
Ultra Champion

did you setup this server as mail server / connected it to a mail server?

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...