- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After Upgrading to Splunk Light 6.6 last week I did not get any emails from my splunk server. In python.log I see the following errors:
ERROR sendemail:443 - [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:676) while sending mail
I am connecting to the mail server over port 587 using "Enable TLS" without username.
Any ideas whats going wrong?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Please see the notes for issue SPL-138647 which contains the steps for figuring out what SSL/TLS versions and cipher suites your e-mail server supports:
https://docs.splunk.com/Documentation/Splunk/6.6.0/ReleaseNotes/Knownissues
If security is not a concern, you can also just revert back to the previous release settings:
$SPLUNK_HOME/etc/system/local/alert_actions.conf
[email]
sslVersions = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Please see SPL-138647 in the release notes to determine what SSL/TLS version and cipher suites your e-mail server supports:
http://docs.splunk.com/Documentation/Splunk/6.6.0/ReleaseNotes/Knownissues
Alternatively, if security is not a concern, you can also revert to the 6.5.x configuration:
$SPLUNK_HOME/etc/system/local/alert_actions.conf
[email]
sslVersions = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Please see the notes for issue SPL-138647 which contains the steps for figuring out what SSL/TLS versions and cipher suites your e-mail server supports:
https://docs.splunk.com/Documentation/Splunk/6.6.0/ReleaseNotes/Knownissues
If security is not a concern, you can also just revert back to the previous release settings:
$SPLUNK_HOME/etc/system/local/alert_actions.conf
[email]
sslVersions = *,-ssl2
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/335ba/335ba69abbc8866bf1f000a216101fba37152fcc" alt="andrewb_splunk andrewb_splunk"
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Do you have the Admin role in Splunk Light, or the User role?
data:image/s3,"s3://crabby-images/d7f73/d7f73632dd731f9b3dd280d9d048df61ba67932c" alt=""