Monitoring Splunk

splunk email alerts failing on send

buckmaster60
New Member

Testing splunk monitoring, alerts, notifications before purchase. Looking for a tool to monitor a large hosting facility. Monitoring vSphere 5, virtual machines, switches, routers, physical boxes to start with.

Running Splunk 4.2.5, using Zimbra email server. I'm able to use vCenter to send alerts, use the Basebaord Management Console on the ESX servers to send alerts no problem. I created an account splunk.events on the Zimbra server. Can log into Zimbra as splunk.events and send email. However, splunk is failing to send alert emails? The log /opt/splunk/var/log/splunk has the following error "ERROR SMTP AUTH EXTENSION NOT SUPPORTED BY SERVER WHILE SENDING TO". I can't figure out why it's failing on SMTP when my other systems are able to send alerts?

Thanks

Tags (3)
0 Karma

gavind
Explorer

I had this issue once. Try to stop "sendmail" service. It's posing a service port conflict.

0 Karma

buckmaster60
New Member

Thanks for the responses. I have setup the fields in the Splunk Manager for email. I can log into Zimbra as splunk.events and send email manually. I guess I'm missing something simple. My other alerting accounts on vCenter and ESX can send alerts with no problems. I wonder how splunk is different?

0 Karma

RubenOlsen
Path Finder

Have you by any chance set up authentication in the Splunk Manager > System settings > Email alert settings dialogue? I.e. entered anything in the Username and Password fields?

Based on the error message you posted, it seems that the error message is coming from Zimbra, and that Zimbra is not configures to support authentication by SMTP.

Unless your organization is extremely security conscious with regards to how the internal networks components are set up - any kind of SMTP authentication is probably turned off.

\Ruben

buckmaster60
New Member

I guess splunk does not monitor these post?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...