Reporting

Email alert action not sending in 7.2.4 (dev/test license)

chanfoli
Builder

I just did a fresh install of 7.2.4 and installed my dev/test license. I am trying to test email alert functionality, which worked on this system when a previous version was installed. The search fires and appears to trigger the alert action but it looks like sendemail is failing. This is the message in the python.log:

2019-02-08 15:45:01,734 -0500 ERROR sendemail:1397 - [HTTP 404] https://127.0.0.1:8089/servicesNS/admin/search/saved/searches/Splunk%20Web%20Login?output_mode=json

I am not sure if this a bug which needs to have support check into it, or if it is due to using a dev/test license under this version. I did not have this issue with a dev/test license under older versions. I did set up this instance with a different admin username than admin however, so I am not sure if this is related.

0 Karma

umlsasec
New Member

Unfortunately, this appears to a limitation with the dev license. With identical settings in my prod Splunk with enterprise license, it works just fine, but the dev server returns the same 404 error you're getting.

This is the second time I've spent hours chasing an issue only to realize it is an unpublished license limitation. 😕

0 Karma

ShawnWarner7
New Member

I'm seeing the same issue. Did you ever get this resolved?

0 Karma

jkat54
SplunkTrust
SplunkTrust

404 status code means the page is not found. In this case the URL seems to suggest its looking for the json output of a search named “Splunk Web Login”.

Is there a search named “Splunk Web Login” in savedsearches.conf in $splunk_home/etc/apps/search/default/

Or

$splunk_home/etc/apps/search/local/

?

0 Karma

adonio
Ultra Champion

did you setup this server as mail server / connected it to a mail server?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...