Splunk Enterprise

How do I resolve Send Email error - SMTP server?

AishwaryaAlhat
Engager

Hi all, I'm to trying to set an email alert notification using Splunk enterprise 9.0 but I am getting the following error: 

AishwaryaAlhat_0-1680232219224.png

I checked the error logs and details are below:

AishwaryaAlhat_1-1680232563182.png

Could anyone help me to understand this and guide me in right direction to resolve this error? Thanks.

Regards,

Aish

 

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

this error message means that your splunk instance has configured to use user which haven't right to send email to your configured smtp-server.

Here is instructions how to configure your splunk to send emails. https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification

Be sure that your are using smtp-server which allow sending emails from your server. Usually there are some requirements which your client must fulfil before it can send email. You can get those from your SMTP server admin.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this error message means that your splunk instance has configured to use user which haven't right to send email to your configured smtp-server.

Here is instructions how to configure your splunk to send emails. https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification

Be sure that your are using smtp-server which allow sending emails from your server. Usually there are some requirements which your client must fulfil before it can send email. You can get those from your SMTP server admin.

r. Ismo

0 Karma

AishwaryaAlhat
Engager

Hi, 

I have configured the instance to SMTP server. Here are the details:

AishwaryaAlhat_0-1680477086604.png

Also, could you please explain in more detail (example) about: "Usually there are some requirements which your client must fulfil before it can send email." 

Thank you.

Regards,

Aish

0 Karma

psecure
Loves-to-Learn

Hello all,

I have a problem with my configuration smtp.
When I send e-mail I get this error :

2024-02-14 16:44:15,213 +0100 ERROR cli_common:482 - Failed to decrypt value: ***************************=, error: Read custom key data size=30

Someone has an idea?

Tags (1)
0 Karma

mmacielinski
Observer

This line in $SPLUNK_HOME/lib/python3.7/site-packages/splunk/clilib/cli_common.py was the source of an error when configuration initialization is slow...

 

 if err:
    logger.error(
        'Failed to decrypt value: {}, error: {}'.format(value, err))
    return None
  return out.strip()

 

There is a wallclock message that gets in the middle of the decrypt operation causing it to fail.

Changed code to this, and problem went away.

 

if 'took wallclock_ms' no in err:
    logger.error(
        'Failed to decrypt value: {}, error: {}'.format(value, err))
    return None
  return out.strip()

 

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...