Splunk Enterprise

How do I resolve Send Email error - SMTP server?

AishwaryaAlhat
Engager

Hi all, I'm to trying to set an email alert notification using Splunk enterprise 9.0 but I am getting the following error: 

AishwaryaAlhat_0-1680232219224.png

I checked the error logs and details are below:

AishwaryaAlhat_1-1680232563182.png

Could anyone help me to understand this and guide me in right direction to resolve this error? Thanks.

Regards,

Aish

 

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

this error message means that your splunk instance has configured to use user which haven't right to send email to your configured smtp-server.

Here is instructions how to configure your splunk to send emails. https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification

Be sure that your are using smtp-server which allow sending emails from your server. Usually there are some requirements which your client must fulfil before it can send email. You can get those from your SMTP server admin.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this error message means that your splunk instance has configured to use user which haven't right to send email to your configured smtp-server.

Here is instructions how to configure your splunk to send emails. https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification

Be sure that your are using smtp-server which allow sending emails from your server. Usually there are some requirements which your client must fulfil before it can send email. You can get those from your SMTP server admin.

r. Ismo

0 Karma

AishwaryaAlhat
Engager

Hi, 

I have configured the instance to SMTP server. Here are the details:

AishwaryaAlhat_0-1680477086604.png

Also, could you please explain in more detail (example) about: "Usually there are some requirements which your client must fulfil before it can send email." 

Thank you.

Regards,

Aish

0 Karma

psecure
Loves-to-Learn

Hello all,

I have a problem with my configuration smtp.
When I send e-mail I get this error :

2024-02-14 16:44:15,213 +0100 ERROR cli_common:482 - Failed to decrypt value: ***************************=, error: Read custom key data size=30

Someone has an idea?

Tags (1)
0 Karma

mmacielinski
Observer

This line in $SPLUNK_HOME/lib/python3.7/site-packages/splunk/clilib/cli_common.py was the source of an error when configuration initialization is slow...

 

 if err:
    logger.error(
        'Failed to decrypt value: {}, error: {}'.format(value, err))
    return None
  return out.strip()

 

There is a wallclock message that gets in the middle of the decrypt operation causing it to fail.

Changed code to this, and problem went away.

 

if 'took wallclock_ms' no in err:
    logger.error(
        'Failed to decrypt value: {}, error: {}'.format(value, err))
    return None
  return out.strip()

 

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...