<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About warning showing in Splunk Cloud message box in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/696888#M3209</link>
    <description>&lt;P&gt;The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world.&amp;nbsp; It will appear if the allowedDomainList is empty.&amp;nbsp; If you are OK with that then you can ignore the message.&lt;/P&gt;&lt;P&gt;If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.&lt;/P&gt;&lt;P&gt;I'm not aware of a way to have an empty allowedDomainList and not get the warning message.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2024 18:57:48 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-20T18:57:48Z</dc:date>
    <item>
      <title>About warning showing in Splunk Cloud message box</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/696877#M3205</link>
      <description>&lt;P&gt;Recently, I observed a message in Splunk Cloud (version 9.2.2403.105) stating, "Found an empty value in 'allowedDomainList' in alert_actions.conf." However, when I check the "Allowed Domain" setting in the UI by navigating to "Settings &amp;gt; Server settings &amp;gt; Email," it indicates "Leave empty for no restrictions." Despite this, I am still seeing the warning message.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anurag_0-1724170851761.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32334i739F1D96BC448E04/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Anurag_0-1724170851761.png" alt="Anurag_0-1724170851761.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Anurag_1-1724170859538.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32335i2865AC607BAC7A67/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Anurag_1-1724170859538.png" alt="Anurag_1-1724170859538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#splunkcloud&amp;nbsp; #splunk&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 16:21:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/696877#M3205</guid>
      <dc:creator>Anurag</dc:creator>
      <dc:date>2024-08-20T16:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: About warning showing in Splunk Cloud message box</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/696888#M3209</link>
      <description>&lt;P&gt;The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world.&amp;nbsp; It will appear if the allowedDomainList is empty.&amp;nbsp; If you are OK with that then you can ignore the message.&lt;/P&gt;&lt;P&gt;If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.&lt;/P&gt;&lt;P&gt;I'm not aware of a way to have an empty allowedDomainList and not get the warning message.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/696888#M3209</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-20T18:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: About warning showing in Splunk Cloud message box</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/702931#M3321</link>
      <description>&lt;P&gt;I just upgraded to 9.3.1 and was also getting that warning.&amp;nbsp; I set a value for allowedDomainList in system/local/alert_actions.conf, restarted the daemon, but I still get the message.&lt;/P&gt;&lt;P&gt;Just wanted to post in case other experience the same behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 16:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/702931#M3321</guid>
      <dc:creator>JyPl4wNYu7GV1uL</dc:creator>
      <dc:date>2024-10-28T16:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: About warning showing in Splunk Cloud message box</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/702935#M3322</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;Disregard.&amp;nbsp; I had put the setting in the [default] stanza, moved it to the [email] stanza, now the warning has resolved.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 16:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/702935#M3322</guid>
      <dc:creator>JyPl4wNYu7GV1uL</dc:creator>
      <dc:date>2024-10-28T16:41:11Z</dc:date>
    </item>
    <item>
      <title>Security risk warning: Found an empty value for 'allowedDomainList' in the alert_actions.conf configuration file....</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/749921#M3897</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have this instance on my personal computer and am a little confused about how to protect myself. I do not know which (or how to determine) allowedDomainList I should use. Where do I find the necessary information to fill that field in?&lt;/P&gt;&lt;P&gt;Sorry, still a beginner..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 19:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/749921#M3897</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-16T19:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security risk warning: Found an empty value for 'allowedDomainList' in the alert_actions.conf configuration file....</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/750004#M3899</link>
      <description>&lt;P&gt;The allowedDomainList setting can be in any alert_actions.conf file on your search head(s).&amp;nbsp; Precedence rules apply, however.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 11:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/About-warning-showing-in-Splunk-Cloud-message-box/m-p/750004#M3899</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-07-17T11:46:51Z</dc:date>
    </item>
  </channel>
</rss>

