Monitoring Splunk

splunk email alerts failing on send

buckmaster60
New Member

Testing splunk monitoring, alerts, notifications before purchase. Looking for a tool to monitor a large hosting facility. Monitoring vSphere 5, virtual machines, switches, routers, physical boxes to start with.

Running Splunk 4.2.5, using Zimbra email server. I'm able to use vCenter to send alerts, use the Basebaord Management Console on the ESX servers to send alerts no problem. I created an account splunk.events on the Zimbra server. Can log into Zimbra as splunk.events and send email. However, splunk is failing to send alert emails? The log /opt/splunk/var/log/splunk has the following error "ERROR SMTP AUTH EXTENSION NOT SUPPORTED BY SERVER WHILE SENDING TO". I can't figure out why it's failing on SMTP when my other systems are able to send alerts?

Thanks

Tags (3)
0 Karma

gavind
Explorer

I had this issue once. Try to stop "sendmail" service. It's posing a service port conflict.

0 Karma

buckmaster60
New Member

Thanks for the responses. I have setup the fields in the Splunk Manager for email. I can log into Zimbra as splunk.events and send email manually. I guess I'm missing something simple. My other alerting accounts on vCenter and ESX can send alerts with no problems. I wonder how splunk is different?

0 Karma

RubenOlsen
Path Finder

Have you by any chance set up authentication in the Splunk Manager > System settings > Email alert settings dialogue? I.e. entered anything in the Username and Password fields?

Based on the error message you posted, it seems that the error message is coming from Zimbra, and that Zimbra is not configures to support authentication by SMTP.

Unless your organization is extremely security conscious with regards to how the internal networks components are set up - any kind of SMTP authentication is probably turned off.

\Ruben

buckmaster60
New Member

I guess splunk does not monitor these post?

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...