Reporting

Sendemail command does not work

tkdguq0110
Path Finder

Hi all

I'm testing sendemail command but it's not sending email.

here's my search code

index=main
| table _time
| sendemail to=tkdguq0110@gmail.com subject=sendemail_test server=mail.google.com

and here's a log above

2020-05-04 19:32:27,700 +0900 ERROR sendemail:1435 - 'utf8' codec can't decode byte 0xbf in position 14: invalid start byte
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\search\bin\sendemail.py", line 1428, in
results = sendEmail(results, settings, keywords, argvals)
File "C:\Program Files\Splunk\etc\apps\search\bin\sendemail.py", line 474, in sendEmail
errorMessage = str(e) + ' while sending mail to: ' + ssContent.get("action.email.to")
UnicodeDecodeError: 'utf8' codec can't decode byte 0xbf in position 14: invalid start byte

I do not know what the problem is.
I would appreciate if you give me any help
Thanks

Labels (1)
0 Karma
1 Solution

PavelP
Motivator

Hello @tkdguq0110 ,

can you try with quoted to string:

sendemail to="tkdguq0110@gmail.com" subject=sendemail_test server=mail.google.com

Additionally you have to specify other parameters because gmail accept authtenticated emails using encrypted channel only: https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html

Please consider workarounds:
https://stackoverflow.com/questions/53264898/splunk-sendemail-fails-errno-99-with-mailserver-smtp-gm...

Let me know if it worked

View solution in original post

PavelP
Motivator

Hello @tkdguq0110 ,

can you try with quoted to string:

sendemail to="tkdguq0110@gmail.com" subject=sendemail_test server=mail.google.com

Additionally you have to specify other parameters because gmail accept authtenticated emails using encrypted channel only: https://answers.splunk.com/answers/38624/how-to-configure-email-alert-using-gmail-smtp.html

Please consider workarounds:
https://stackoverflow.com/questions/53264898/splunk-sendemail-fails-errno-99-with-mailserver-smtp-gm...

Let me know if it worked

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...