Reporting

Splunk 6.6.2 error sending alert email "ERROR:root:EOF occurred in violation of protocol (_ssl.c:676)"

marksnelling
Communicator

I just upgraded from Splunk 6.5.2 to 6.6.2 and now the emailing of alerts when using STARTTLS is broken. Looking at the splunkd.log file I can see the error ERROR:root:EOF occurred in violation of protocol (_ssl.c:676).

Email works correctly if I disable the SMTP STARTTLS option in email settings which is less than ideal.

0 Karma

appdev84
Engager

It looks like there is a known issue when upgrading Splunk 6.5.x to Splunk 6.6.2.

http://docs.splunk.com/Documentation/Splunk/6.6.2/ReleaseNotes/KnownIssues#Upgrade_Issues

I followed the guide and added $SPLUNK_HOME/etc/system/local/alert_actions.conf and added

[email]
sslVersions = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH

I then restarted the server and it was emailing again.

Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...