Hi Everyone,
I am working in splunk distributed environment. i want to schedule pdf and make alerts so that have to configure email settings. In the email settings provided my exchange server and port also.
i am confusing what to give username and password in email settings can anyone tell me how to do that please..
You should set auth_username
that you can use to authenticate with your SMTP server. Say you are using gmail's SMTP server as mailserver then auth_username should your gmail id.
If you use your company's SMTP server as mailserver then auth_username
should be a username (email id) that will be authenticated with your company's SMTP Server.
First I tested with my username and password then we created a dedicated username and password for sending PDF's.
but when i enable ssl then it is showing ssl error.
You need to talk to your lab admin folks and work it out. Talk to them and check if some ports are blocked. OR some other network related access issues.
i tried. still its not working. but my exchange server is SSL enabled. ERROR:root:(535, '5.7.3 Authentication unsuccessful')
Disable SSL, give reportServerURL as http://
i have 3 indexers, 1 master node ,1 search head. i have configured email alerts on search head.
Do you have dedicated search heads, deployment servers etc? On which node this search runs?
If PDF Report Server app is being used on a remote machine, set URL above. For example, https://remoteserver:8089/ - Leave blank to use a local PDF server (status page). Does not affect integrated PDF generation. reprotServerURL port 8000 or 8089 can u confirm this please...
yes, getting error but unable to paste it over here:
error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number while sending mail to: thambisetty.balaji@wipro.com
You need to set
reportServerEnabled = 1
reportServerURL =
For more details check alert_actions.conf file.
Are you seeing any errors in splunkd.log?
[email]
mailserver = example.domain.com:port
reportServerURL =
use_ssl = 1
from = example@domain.com
auth_username = example@domain.com
auth_password = $1$qQW8E5cFZ2xL
this is alert_actions.conf
I assume you have set the mailserver details properly.
mailserver =
What is the value you have set for reportServerEnabled and reportServerURL.
Do you see any errors in splunkd.log? Could you post those errors.
no, i have used my company's username and password still it is not working..